You visit a shoe store.
Then a newspaper.
Then a recipe site.
Three unrelated websites.
One advertising company may have been present on all three.
That is the basic trick that made third-party cookies one of the classic technologies of cross-site tracking.
The cookie is ordinary; the context makes it third-party
There is no magical file format called a third-party cookie.
WebKit’s tracking documentation explains the distinction clearly: if news.example is in the address bar while the page loads a resource from adtech.example, the news site is the first party and the ad-tech domain is a third party. If the browser allows that third party to read and write its cookies in this context, those cookies can carry an identifier across sites. See WebKit’s Tracking Prevention documentation.
Imagine the browser receives this identifier from the tracker:
user=847219
Later, another unrelated site loads the same tracker.
If the browser sends user=847219 again, the tracker can recognize the same browser.
Now the tracker can associate both visits with one identifier.
Repeat that across hundreds of participating sites and the result can become a browsing history.
A browsing history reveals patterns, not just pages
One visit says little.
A sequence can say much more.
Travel research followed by mortgage calculators, moving companies, and school-district pages may suggest a relocation.
Repeated visits to automotive sites can reveal purchase interest. Visits to hobby stores, political publications, technical forums, financial pages, or health-related sites can contribute additional categories and inferences.
Mozilla’s current Firefox documentation describes cross-site cookies in similar terms: when the same tracker appears on multiple sites, it can use cookies to build a more complete profile of browsing activity over time. See Mozilla’s explanation of third-party trackers.
That profile does not require the person to intentionally visit the tracking company’s own website.
The tracker rides inside other pages.
Browsers have sharply restricted this technique
The old third-party-cookie model no longer works uniformly across browsers.
Safari blocks third-party cookies by default as part of Intelligent Tracking Prevention. Firefox enables Total Cookie Protection by default, isolating third-party cookies into separate per-site cookie jars so the same cookie cannot simply follow the browser across unrelated sites.
Chrome took a different path. Google announced in April 2025 that it would maintain user choice for third-party cookies rather than roll out a new standalone prompt or complete a universal deprecation. Chrome blocks third-party cookies by default in Incognito mode, while regular browsing exposes controls that let users allow or block them. See Google’s April 2025 Privacy Sandbox update and Chrome’s cookie controls.
So in 2026, saying browsers killed third-party cookies is too broad.
The reality depends on the browser and settings.
Blocking cookies does not end tracking
Trackers can also use link decoration, browser fingerprinting, first-party storage, account logins, server-side data sharing, IP-derived signals, and other techniques.
WebKit’s own tracking-prevention work discusses defenses against several of those methods because restricting one identifier creates incentives to find another.
That is why third-party cookies belong at the beginning of Surveillance Economy — The Internet Watching You Back, not the end.
They are the easiest version of the idea to see.
You thought you were visiting three websites.
The interesting question is whether a fourth company quietly recognized you at all three.
