Tabnabbing
How It Works
Vulnerable Code Pattern
<!-- VULNERABLE: No rel attribute -->
<a href="https://attacker.com" target="_blank">Click me</a>
<!-- VULNERABLE: Empty rel attribute -->
<a href="https://attacker.com" target="_blank" rel="">Click me</a>
<!-- VULNERABLE: Only noreferrer (still allows opener access in some browsers) -->
<a href="https://attacker.com" target="_blank" rel="noreferrer">Click me</a>Secure Code Pattern
Detection
Manual Testing
Automated Scanning
Exploitation
Basic Attack Page
Phishing Page
Delayed Attack (More Stealthy)
Attack Scenarios
Scenario
Description
Browser Behavior
Browser
Default Behavior (2024+)
window.open() Vulnerability
Related Topics
Last updated
Was this helpful?