Collected research
The great SameSite confusion
SameSite cookies are scoped to the site, meaning the registrable domain or eTLD+1, and not to the origin, so a request from a sibling host or subdomain is same-site and still carries the cookies. A subdomain takeover, XSS or HTML injection anywhere on the same site therefore defeats SameSite, including the Strict value, which the post argues is also unfairly avoided.
Record
- Researcher
- Julien Cretel
- Published by
- jub0bs.com
- Date
- Topic
- Other
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Julien Cretel, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .