Web platform

Cross-origin isolation

Cross-origin isolation is a browser state enabled by compatible opener and embedder policies. It allows capabilities such as shared memory in supported contexts.

Ask the Web platform assistant 1 min read · Updated September 9, 2026

What it is

Cross-origin isolation is a browser state enabled by compatible opener and embedder policies. It allows capabilities such as shared memory in supported contexts.

Why it matters

It is a page-wide resource-loading contract, not merely a switch for faster inference.

Example

A page can use COOP: same-origin and COEP: require-corp, then check crossOriginIsolated before enabling threaded WASM.

Technical detail

Cross-origin subresources may need CORS or a suitable Cross-Origin-Resource-Policy header to load under COEP.

When to use it

Provide a single-thread fallback and inspect blocked fonts, images, and scripts after enabling isolation.

Sources

More in Web platform

Assembled from the ReLU.chat curated knowledge base. These explanations are concise on purpose; check the sources for anything important.