Cookie Security
Medium · SameSite

Lax Inside an iframe

An external site embeds a CookieBank endpoint in an iframe. The request is GET, but the browser's top-level page remains on the attacker site. Observe whether SameSite=Lax accompanies the embedded request.

Objective

Load the cross-site iframe and confirm that the Lax session cookie is withheld.

Target

CookieBank

Launch target

Submit flag