Collected research
Bypass SameSite Cookies Default to Lax and get CSRF
Chrome's Lax-by-default cookies keep a two-minute Lax+POST exemption, so a session cookie set or changed within the last two minutes is still sent on a cross-site top-level POST. An attacker who forces a fresh session, through a GET logout, an OAuth re-login or a new-session endpoint, reopens CSRF against sites relying on the default.
Record
- Researcher
- Renwa and @RenwaX23
- Published by
- Medium
- Date
- Topic
- Identity
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Renwa and @RenwaX23, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .