Web Hack List

Collected research

Bypass SameSite Cookies Default to Lax and get CSRF

Chrome's Lax-by-default cookies keep a two-minute Lax+POST exemption, so a session cookie set or changed within the last two minutes is still sent on a cross-site top-level POST. An attacker who forces a fresh session, through a GET logout, an OAuth re-login or a new-session endpoint, reopens CSRF against sites relying on the default.

Record

Researcher
Renwa and @RenwaX23
Published by
Medium
Date
Topic
Identity

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Renwa and @RenwaX23, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .