402

COOKIEGUARD: Characterizing and Isolating the First-Party Cookie Jar

Main:11 Pages
11 Figures
Bibliography:3 Pages
6 Tables
Appendix:3 Pages
Abstract

As third-party cookies are being phased out or restricted by major browsers, first-party cookies are increasingly repurposed for tracking. Prior work has shown that third-party scripts embedded in the main frame can access and exfiltrate first-party cookies, including those set by other third-party scripts. However, existing browser security mechanisms, such as the Same-Origin Policy, Content Security Policy, and third-party storage partitioning, do not prevent this type of cross-domain interaction within the main frame. While recent studies have begun to highlight this issue, there remains a lack of comprehensive measurement and practical defenses.

View on arXiv
Comments on this paper