Bypassing SameSite Cookie Restrictions Using On-Site Gadgets – A Practical CSRF Bypass
SameSite=Strict Cookies are supposed to be a strong shield against CSRF (Cross-Site Request Forgery). When a cookie has this attribute, the browser refuses to send it on cross-site requests. In theory, this kills CSRF dead. In practice, if the target…
