Link with target=”_blank” and rel=”noopener noreferrer” still vulnerable?

You may be misunderstanding the vulnerability. You can read more about it here:—the-most-underestimated-vulnerability-ever/

Essentially, adding rel="noopener noreferrer" to links protects your site’s users against having the site you’ve linked to potentially hijacking the browser (via rogue JS).

You’re asking about removing that attribute via Developer Tools – that would only potentially expose you (the person tampering with the attribute) to the vulnerability.

Update as of 2021: All current versions of major browsers now automatically use the behavior of rel="noopener" for any target="_blank" link, nullifying this issue. See more at

