← Back to all briefings
Developer 5 min read Published Updated Credibility 40/100

Chrome 80 enforces SameSite-by-default cookie handling

Google released Chrome 80 with SameSite=Lax by default and new requirements for Secure cookies set in cross-site contexts, pushing web apps to label cookies explicitly and update authentication flows.

Timeline plotting source publication cadence sized by credibility.
2 publication timestamps supporting this briefing. Source data (JSON)

Executive briefing: Chrome 80 began enforcing the SameSite-by-default model, treating cookies without a SameSite attribute as Lax and requiring Secure on SameSite=None cookies. The change alters how authentication, CSRF defenses, and third-party embeds behave and demands explicit cookie labeling.

Why it matters

  • Cross-site sign-in, embedded widgets, and legacy CSRF protections can break unless cookies are set with the correct SameSite value.
  • SameSite=None now requires Secure and HTTPS, accelerating the phase-out of third-party cookies on insecure origins.
  • Server libraries and reverse proxies may need upgrades to support the new attribute parsing and to avoid dropping the None value for older user agents.

Operator actions

  • Inventory application cookies and explicitly set SameSite values (None, Lax, or Strict) that match intended use.
  • Mark all SameSite=None cookies as Secure and serve them over HTTPS; update load balancer or CDN configurations as needed.
  • Test federated login flows, embedded iframes, and payment integrations in Chrome 80+ to verify session continuity.
  • Patch application frameworks or libraries to versions that correctly emit the None attribute and avoid legacy-stripping behavior.

Key sources

Timeline plotting source publication cadence sized by credibility.
2 publication timestamps supporting this briefing. Source data (JSON)
Horizontal bar chart of credibility scores per cited source.
Credibility scores for every source cited in this briefing. Source data (JSON)

Continue in the Developer pillar

Return to the hub for curated research and deep-dive guides.

Visit pillar hub

Latest guides

  • Chrome 80
  • SameSite
  • Cookies
Back to curated briefings