Google Chrome to block JavaScript redirects on web page URL clicks

Google Chrome
(Image credit: Shutterstpck)

Google Chrome will soon be able to block JavaScript redirects when users click on a web page link that opens a URL in either a new window or new tab.

For those unfamiliar, when inserting a link into an HTML page, an author can include the target=“_blank” attribute to tell a web browser to open a link in a new tab. While useful for site owners, this attribute has a known security issue due to the fact that a newly opened page can utilize a JavaScript redirect to open a different URL than the one specified in a site's HTML code.

This means that a threat actor could redirect users to phishing pages or sites hosting malicious files just by adding a JavaScript redirect to links on a webpage.

Thankfully though, a re:=“noopener” HTML link attribute was created to prevent new tabs from using JavaScript to redirect to another UR.

Preventing JavaScript redirects

Back in 2018 Apple changed the way in which Safari treats all HTML links that use the target=“_blank” attribute to make it so that they automatically imply the noopener attribute. Once enabled, this feature prevents embedded links from redirecting to a different URL.

Microsoft Edge developer Eric Lawrence recently added this exact same feature to Chromium which means that it will soon find its way to Google Chrome, Brave, Vivaldi, Microsoft Edge and all other Chromium-based browsers. Lawrence provided further details on how this feature will work in Chromium in his commit, saying:

“To mitigate "tab-napping" attacks, in which a new tab/window opened by a victim context may navigate that opener context, the HTML standard changed to specify that anchors that target _blank should behave as if |rel="noopener"| is set. A page wishing to opt out of this behavior may set |rel="opener"|.”

Currently this feature is enabled in Chrome Canary but is expected to be included with the release of Chrome 88 in January of next year.

Via BleepingComputer

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Software & Services
TinEye website
I like this reverse image search service the most
A person in a wheelchair working at a computer.
Here’s a free way to find long lost relatives and friends
A white woman with long brown hair in a ponytail looks down at her computer in a distressed manner. She is holding her forehead with one hand and a credit card with the other
This people search finder covers all the bases, but it's not perfect
That's Them home page
Is That's Them worth it? My honest review
woman listening to computer
AWS vs Azure: choosing the right platform to maximize your company's investment
A person at a desktop computer working on spreadsheet tables.
Trello vs Jira: which project management solution is best for you?
Latest in News
Tesla Roadster 2
Tesla is still taking deposits on its long overdue Roadster, despite promising it would arrive in 2020
Samsung HW-Q990D soundbar with Halloween theme over the top
Samsung promises to repair soundbars bricked by its disastrous software update for free – but it'll probably involve shipping
Google Gemini AI
Gmail is adding a new Gemini AI tool to help smarten up your work emails
DJI Mavic 3 Pro
More DJI Mavic 4 Pro leaks seemingly reveal launch date, price and key features of the triple camera drone – here's what to expect
Android 16 logo on a phone
Here's how Android 16 will upgrade the screen unlocking process on your Pixel
Man sitting on sofa, drinking coffee, looking at phone in surprise
Thousands of coffee lovers warned to stop using their espresso machines immediately after reports of burns and lacerations