Web Hack List

Other nomination

The great SameSite confusion

SameSite cookies are scoped to the site, meaning the registrable domain or eTLD+1, and not to the origin, so a request from a sibling host or subdomain is same-site and still carries the cookies. A subdomain takeover, XSS or HTML injection anywhere on the same site therefore defeats SameSite, including the Strict value, which the post argues is also unfairly avoided.

Record

Researcher
Julien Cretel
Date

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Julien Cretel, first published at the original source. Preserved copies are kept so the citation survives its host.