Target=“_blank” – the most underestimated vulnerability ever (2021)
jitbit.com
jitbit.com
I remember reading about this back in ~2016 if not earlier. Was also featured on HN at least twice (via https://mathiasbynens.github.io/rel-noopener/ where I think I read about it first):
I mean, this doesn’t happen with normal links where the target isn’t set, so there must have been some intention behind this.