@samitouri / QOS-React / commits / 8657ad4278

Fix(React DevTools) - prevent phishing attacks (#19934)

When a link opens a URL in a new tab with target="_blank", it is very simple for the opened page to change the location of the original page because the JavaScript variable window.opener is not null and thus "window.opener.location can be set by the opened page. This exposes the user to very simple phishing attacks.

John Wilson committed Oct 1, 2020 at 23:25 UTC 8657ad4278334a072dc88ce8bb0ea4090fd944e2
1 file changed +1
packages/react-devtools/app.html
+1
@@ -121,6 +121,7 @@
121 id="rn-help-link"
122 class="link"
123 target="_blank"
124 + rel="noopener noreferrer"
125 href="https://reactnative.dev/docs/debugging#accessing-the-in-app-developer-menu"
126 >in-app developer menu</a> to connect.
127 </div>