Since Spectre (2018), SharedArrayBuffer requires cross-origin isolation (Firefox 79 555 , Chrome 92 1 ). Send Cross-Origin-Opener-Policy: same-origin and Cross-Origin-Embedder-Policy: require-corp, under which cross-origin subresources load only with CORS or Cross-Origin-Resource-Policy: cross-origin.
<img id="plain" src="http://127.0.0.1:8937/pic.png">
<img id="corp" src="http://127.0.0.1:8937/corp-pic.png">
<script>
onload = () => {
console.log(`isolated: ${crossOriginIsolated}, no-CORP image: ${plain.naturalWidth > 0}`);
console.log(`CORP image: ${corp.naturalWidth > 0}`);
const shared = new SharedArrayBuffer(4); // ReferenceError when not isolated
const code = 'onmessage = (e) => { new Int32Array(e.data)[0] = 42; postMessage(0); };';
const worker = new Worker(URL.createObjectURL(new Blob([code])));
worker.onmessage = () => console.log('worker wrote', new Int32Array(shared)[0]);
worker.postMessage(shared);
};
</script>isolated: true, no-CORP image: false CORP image: true worker wrote 42
Isolation also enables WebAssembly threads. COEP credentialless (Chrome 96, Firefox 119) loads third-party resources without cookies instead of blocking them; Chrome 137's Document-Isolation-Policy isolates one document without either header. COOP breaks OAuth popups that use window.opener unless you use same-origin-allow-popups.