Same-origin policy limits which pages can read each other
The rule that stops a page on one site reading data from another is the foundation the whole web security model rests on.
Without it, any page you visited could read your webmail in another tab. Almost every browser security feature is either an implementation of this or a carefully controlled exception to it, and most browser vulnerabilities are ways of escaping it.
More on Browser security
- CORS relaxes browser reading rules, not authenticationA propped hatch, not a checkpoint
- SameSite cookies reduce some cross-site request risksSome journeys, not every journey
- Browser extensions inherit powerful visibilityEverything passes under it
- Local storage is convenient, not a secure vaultOpen shelves by the door
- Content Security Policy constrains script sourcesOnly from the addresses you wrote down
- Clickjacking hides the real control beneath the clickPressed here. Answered there
