Web Hack List

Collected research

The great SameSite confusion

SameSite cookies are scoped to the site, meaning the registrable domain or eTLD+1, and not to the origin, so a request from a sibling host or subdomain is same-site and still carries the cookies. A subdomain takeover, XSS or HTML injection anywhere on the same site therefore defeats SameSite, including the Strict value, which the post argues is also unfairly avoided.

Record

Researcher
Julien Cretel
Published by
jub0bs.com
Date
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Julien Cretel, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .