Mozilla developer Anne van Kesteren discovered that `<iframe sandbox>` with the `allow-popups` flag could be bypassed when using `noopener` links. This could have led to security issues for websites relying on sandbox configurations that allowed popups and hosted arbitrary content.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2020-33/#CVE-2020-15653