Cross-origin Isolation

Since Spectre (2018), SharedArrayBuffer requires cross-origin isolation (Firefox 79 555 , Chrome 92 1 ). Send Cross-Origin-Opener-Policy: same-origin and Cross-Origin-Embedder-Policy: require-corp, under which cross-origin subresources load only with CORS or Cross-Origin-Resource-Policy: cross-origin.

A page served from localhost with COOP and COEP; 127.0.0.1 is another originHTMLLive
<img id="plain" src="http://127.0.0.1:8937/pic.png">
<img id="corp" src="http://127.0.0.1:8937/corp-pic.png">
<script>
  onload = () => {
    console.log(`isolated: ${crossOriginIsolated}, no-CORP image: ${plain.naturalWidth > 0}`);
    console.log(`CORP image: ${corp.naturalWidth > 0}`);
    const shared = new SharedArrayBuffer(4);  // ReferenceError when not isolated
    const code = 'onmessage = (e) => { new Int32Array(e.data)[0] = 42; postMessage(0); };';
    const worker = new Worker(URL.createObjectURL(new Blob([code])));
    worker.onmessage = () => console.log('worker wrote', new Int32Array(shared)[0]);
    worker.postMessage(shared);
  };
</script>

Isolation also enables WebAssembly threads. COEP credentialless (Chrome 96, Firefox 119) loads third-party resources without cookies instead of blocking them; Chrome 137's Document-Isolation-Policy isolates one document without either header. COOP breaks OAuth popups that use window.opener unless you use same-origin-allow-popups.