Google temporarily rolls back its SameSite policy in Chrome, to allow stability for essential service websites that may not meet third party cookie requirements
Hello, and welcome to The Edge … Surur / MSPoweruser : Google rolls back SameSite cookie privacy changes in Chrome to “ensure stability for websites … Martin Brinkmann / gHacks Technology News : Google is rolling back SameSite Cookie changes temporarily Mariella Moon / Engadget : Google rolls back Chrome feature that blocks cross-site tracking Catalin Cimpanu / ZDNet : Google rolls back Chrome privacy feature due to COVID-19 Abner Li / 9to5Google : Google rolling back Chrome's cookie security measure in light of COVID-19 Corbin Davenport / Android Police : Chrome dials back cookie privacy changes to keep sites accessible during coronavirus outbreak Tweets: Dare Obasanjo / @carnage4life : Google decided to hold off on cookie blocking changes in Chrome due to not wanting to harm websites of essential services. This highlights collateral damage of browser vendor's push to block cookies which ends up breaking sites & hurting media ad revenue https://www.theverge.com/... Stephen Shankland / @stshank : Because of the coronavirus pandemic's disruptions, Google is reversing for now the @googlechrome “SameSite” cookie change, a big security shift that can mess up some websites that haven't updated to handle it. https://blog.chromium.org/...
Context & Ripple Effects
Chrome's SameSite enforcement was meant to force sites onto stricter cross-site cookie handling, but with the pandemic pushing traffic to banking, health, and government services, Google paused the rollout rather than risk breaking logins at essential sites. The pause was explicitly temporary — by late May Google committed to resuming the update alongside Chrome 84 on July 14.
The rollback matters because it set the template for everything after it: Chrome 83 shipped new privacy controls weeks later, but the harder deadline — killing third-party cookies outright — slipped from 2022 to late 2023 and then again to H2 2024 as Google cited the need for more Privacy Sandbox testing.
First-order effects
- Essential-service websites that had not reworked their third-party cookie handling get an enforcement holiday, keeping logins and sessions intact during peak pandemic load.
- Ad-tech and analytics vendors dependent on cross-site cookies keep functioning in Chrome instead of facing broken measurement overnight.
Second-order effects
- Publishers and ad networks gain breathing room to migrate, but also less urgency — the same dynamic that produced Google's later decision to push the full third-party cookie phase-out to H2 2024 after earlier slips.
- Rival browsers that enforced SameSite on schedule can claim stricter privacy postures, pressuring Google to show progress through feature releases like Chrome 83's Incognito cookie blocking rather than deadlines.
Third-order effects
- The pattern holds across the corpus: every hard date Google set for cookie deprecation moved — 2022 to 2023, then to 2024 — suggesting Chrome's privacy timeline is structurally subordinate to the ad-funded web's readiness, not the other way around.
- If enforcement keeps bending to ecosystem stability, regulators and advertisers alike should treat browser-announced cookie deadlines as soft targets, shifting the real constraint to whatever replacement technology (Privacy Sandbox or otherwise) actually ships.
The trend: Browser-enforced cookie privacy is becoming a rolling negotiation between Google's deadlines and the ad-dependent web's ability to comply, with each crisis — pandemic, publisher pressure, testing gaps — buying another deferral.