What is the name of the attack that tricks a browser into sending an unwanted authenticated request?

The story behind the answer

The attack that tricks a browser into sending an unwanted authenticated request is cross-site request forgery.

Cross-site request forgery, commonly abbreviated CSRF or XSRF, abuses the way browsers automatically include credentials such as session cookies. If a victim is logged in to a website, an attacker may lure that browser into submitting a request to the trusted site without the victim intentionally initiating it.

A successful CSRF attack does not necessarily steal the victim's password. Instead, it may cause an unwanted state-changing action, such as changing an account setting or submitting a transaction. Modern defenses include unpredictable anti-CSRF tokens, SameSite cookie attributes, origin checks, and reauthentication for sensitive actions.

CSRF is different from cross-site scripting. XSS injects or executes hostile script in a trusted page, while CSRF abuses a trusted browser session to send a request. The two attacks can also appear together, but they are distinct security problems.

Source: Wikipedia · fact-checked Sept. 2026

Add question to a list

Choose a list to keep this question in: