The target=“_blank” vulnerability by example
dev.to
dev.to
- Earlier discussion [1] on the same topic posted elsewhere
Seems the default should be rel="noopener"...
EDIT: Oh, seems like Instagram has fixed this after all. If you inspect the link on his Instagram profile, you will find rel="nofollow me noopener noreferrer" and if you remove that attribute, it works just as described in the blog. I learned something new.