Third-Party Cookies Were Supposed to Be Gone by Now. Here's What Actually Happened
If you still believe third-party cookies got phased out of Chrome by now, you are not alone, and you are also not correct. That belief is based on a plan that quietly fell apart over the last two years.
The cookie that was supposed to be gone by now is, for most Chrome users, still very much intact.
In this post
- The plan, as it was originally announced
- What actually happened, in order
- Where things stand in Chrome right now
- Safari and Firefox already did this, years ago
- What this means for your own privacy today
This is one of those tech stories where the headlines from a couple of years ago are now actively misleading, not because they were false at the time, but because the plan they described did not survive contact with reality. Worth setting the record straight, since a lot of "how to prepare for cookieless browsing" advice still circulating online is built on a premise that never fully happened.
The plan, as it was originally announced
Starting around 2020, Chrome's maker announced an intention to phase out third-party cookies, the small trackers that let advertisers and analytics companies follow you across different websites, as part of an initiative called Privacy Sandbox. The idea was to replace granular cross-site tracking with a set of new browser-level APIs, things like Topics and Protected Audience, designed to support advertising use cases with less individual tracking involved. The original target was 2022, then pushed to 2023, then 2024, in a pattern of repeated delays driven largely by pushback from the advertising industry and scrutiny from the UK's Competition and Markets Authority over whether the replacement system itself concentrated too much power in the browser maker's hands.
What actually happened, in order
- Multiple delays through 2022 to 2024, each pushing the deprecation timeline back by months, driven by regulatory review and industry feedback that never fully converged.
- July 2024: a significant reversal, announcing that Chrome would not force-deprecate third-party cookies after all, moving instead toward a model where users would be asked to choose their own tracking preference.
- April 2025: that planned user choice prompt itself was dropped, quietly stepping back from the reworked plan as well.
- October 2025: the broader Privacy Sandbox initiative was wound down, with pieces of it, including Topics and Protected Audience, continuing in a reduced form rather than as the full cookie replacement system originally envisioned.
Each individual announcement made sense on its own. Read together, the trajectory is unmistakable: an ambitious plan to fundamentally change how tracking works on the web ran into enough regulatory, technical, and industry resistance that it did not survive in its original form. The Privacy Sandbox news archive documents this timeline directly, in the announcements' own words, for anyone who wants to read the original updates rather than secondhand coverage of them.
Where things stand in Chrome right now
As of now, third-party cookies still function in Chrome for the general user base. This does not mean nothing changed at all, some of the Privacy Sandbox APIs remain available in reduced form, and Chrome has made other privacy-related adjustments over the years independent of this specific initiative. But the headline outcome, a Chrome browser where third-party cookies simply no longer work by default, did not happen the way it was originally announced.
Why this matters beyond trivia: a lot of privacy advice, browser extension marketing, and "get ready for the cookieless future" content published over the last few years was written assuming this deprecation would actually complete on schedule. If you have been holding off on personal cookie management habits because you assumed Chrome would just handle it for you eventually, that assumption did not pan out, at least not so far.
Safari and Firefox already did this, years ago
This is the part that gets lost in coverage focused entirely on Chrome. Safari's Intelligent Tracking Prevention and Firefox's Enhanced Tracking Protection have both blocked third-party cookies by default for years already, well before Chrome's plan was ever announced. A meaningful share of web traffic has effectively been operating in a cookieless environment for cross-site tracking for a long time, which is also part of why browser fingerprinting, covered in an earlier post on this blog, has grown as a tracking method regardless of what Chrome eventually decides, since advertisers needed alternatives for Safari and Firefox users long before Chrome was ever part of the conversation.
| Browser | Third-party cookie status |
|---|---|
| Safari | Blocked by default for years, via Intelligent Tracking Prevention |
| Firefox | Blocked by default for years, via Enhanced Tracking Protection |
| Chrome | Still enabled by default, deprecation plan wound down as of late 2025 |
| Brave | Blocked by default, as part of its broader privacy-focused design |
What this means for your own privacy today
If cross-site tracking specifically concerns you, the practical takeaway is not to wait on Chrome to solve it for you, since that plan did not complete as announced and there is no fixed new date for it to. The options that actually work today, right now, regardless of what Chrome eventually does, are using a browser that already blocks third-party cookies by default, installing a reputable tracker-blocking extension if you stay on Chrome, and understanding that fingerprinting-based tracking exists as a separate, cookie-independent method that none of this addresses anyway.
The broader lesson here is a reasonable one to carry into how you read tech news generally: an announced plan, even from a major browser maker, is a stated intention, not a guarantee. This particular plan spent roughly five years being announced, delayed, reworked, and eventually scaled back, and treating any single headline along that path as the final outcome would have been premature at every single stage.