Researchers disclosed a Chrome vulnerability that could bypass SameSite=Strict cookie protections when a target website had a registered service worker and a victim opened Chrome DevTools. A cross-site POST initially sent without cookies could be replayed by the Inspector Resource Content Loader using the invalid kNoCors and kOnlyIfCached combination; the target site's service worker could then refetch the request in its own origin context, causing Strict cookies to be attached.
The flaw could enable CSRF-style actions, including unauthorized account or password changes and financial transfers. Chrome's Vulnerability Reward Program rated the report S3/P2 and fixed the issue by changing the loader request mode to kSameOrigin while retaining kOnlyIfCached. Researchers also reported a related cache and request-resubmission path involving Ctrl+U and page refresh behavior as Issue-470629629.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Chrome fixed the issue by changing Inspector Resource Content Loader's request mode to kSameOrigin while retaining kOnlyIfCached. The change prevents a service worker from making an outbound network fetch that could replay a cookie-bearing POST request.
Researcher Jorian found that Ctrl+U to view page source could trigger the same cache issue and separately reported refresh behavior with resubmission confirmation as Issue-470629629.
Researchers, including bug_blitzer, reported a Chrome vulnerability in which opening DevTools after a cross-site POST could cause a service worker to replay the request in the target origin context with SameSite=Strict cookies attached. Chrome VRP classified the report as severity S3 and priority P2.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.