Cybersecurity
16 Sep 2026
7 min read
SameSite Cookies Draw a Site Boundary That Is Broader Than Origin
SameSite Cookies Draw a Site Boundary That Is Broader Than Origin Two HTTPS applications can be isolated by the browser’s same-origin policy yet still occupy the same cookie site. A service at accounts.example.com and another at shop.example.com have different origins because their hosts differ, but cookie policy can classify their request context at a broader site boundary. That gap matters when SameSite is treated as if it were equivalent to origin isolation.