Support in current browsers

Checked against the current browser versions recorded in MDN browser data 8.0.7.

BrowserMinimumOutcomeReason
Chrome150Works with limitsEvery required mapped feature is available, but BCD records one or more qualifications.
Edge150WorksEvery required mapped BCD feature is available without a recorded qualification.
Firefox152WorksEvery required mapped BCD feature is available without a recorded qualification.
Safari26.5WorksEvery required mapped BCD feature is available without a recorded qualification.
Chrome for Android150Works with limitsEvery required mapped feature is available, but BCD records one or more qualifications.
Firefox for Android152WorksEvery required mapped BCD feature is available without a recorded qualification.
Safari on iOS26.5WorksEvery required mapped BCD feature is available without a recorded qualification.
Android WebView150Works with limitsEvery required mapped feature is available, but BCD records one or more qualifications.
Samsung Internet29.0WorksEvery required mapped BCD feature is available without a recorded qualification.

What this feature can and cannot do

Helps protect against

  • Cross-origin resource inclusion
  • Selected speculative side-channel exposure

Does not guarantee

  • Authorised CORS reads
  • Application authorisation
  • Resources served without the header

What you need before using it

  • An accurate resource-sharing model

Fallback to keep in place

Use authentication, CORS, and response minimization appropriate to each resource.