SameSite cookies reduce some cross-site request risks

Marking a cookie SameSite stops the browser attaching it to requests originating from other sites.

That removes the mechanism cross-site request forgery depends on, which is why modern browser defaults have made a large class of that attack much harder. It is a useful default and not complete coverage, particularly where requests come from the same site by a route you did not intend.

More on Browser security