Security researchers demonstrated methods to bypass SameSite cookie protections in web applications, enabling successful Cross-Site Request Forgery (CSRF) attacks against a change email function. In one scenario, the application used the default SameSite=Lax setting, which allowed session cookies to be sent in cross-site GET requests during top-level navigation. By manipulating HTTP methods and leveraging the absence of unpredictable tokens, attackers could exploit this configuration to perform unauthorized actions on behalf of users. Another scenario involved SameSite=Strict cookies, where a client-side JavaScript redirect was identified as a potential vector to circumvent the strict cookie policy, again enabling CSRF attacks if exploited correctly.
These findings highlight the importance of properly configuring SameSite cookie attributes and implementing robust anti-CSRF tokens in sensitive web application endpoints. The research underscores that even with modern browser protections, creative exploitation of HTTP methods and client-side behaviors can undermine session security, emphasizing the need for defense-in-depth strategies in web application development and testing.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
A web application's change-email function was found vulnerable to CSRF because the request lacked unpredictable anti-CSRF tokens. Researchers showed SameSite=Strict protections could be bypassed by abusing a client-side JavaScript redirect after comment submission, allowing an attacker to change a victim's email address.
A web application's change-email function was found vulnerable to CSRF because the request lacked unpredictable anti-CSRF tokens. The issue could be exploited despite default SameSite=Lax cookie behavior by using a top-level cross-site GET request with method override to trigger the email change.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
osintteam.blog
Open sourceosintteam.blog
Open sourceosintteam.blog
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.