For years, the tech press treated Google’s plan to phase out third-party cookies in Chrome as a settled, inevitable privacy improvement, just a matter of time before the world’s most-used browser caught up to Safari and Firefox. That plan reversed, quietly enough that plenty of people still assume it went through. If you’re using Chrome in 2026 and haven’t checked your settings directly, the tracking cookies you thought were on their way out are almost certainly still running by default.
What Happened, in Order
Google announced on April 22, 2025 that it would keep third-party cookies enabled by default in Chrome, walking back years of stated plans to phase them out entirely. The company’s own language was direct about it: “We’ve decided to maintain our current approach to offering users third-party cookie choice in Chrome,” a framing that puts the responsibility on the user to opt out rather than defaulting to privacy. Then, on October 17, 2025, Google shut down most of Privacy Sandbox, the replacement ad-targeting technology it had spent years building specifically to let advertisers target users without cookies, citing low adoption. Topics, Protected Audience, and Attribution Reporting, three of Privacy Sandbox’s core targeting and measurement APIs, were all discontinued. Only three pieces survived: CHIPS (partitioned cookies used for embedded content), FedCM (federated login support), and Private State Tokens (an anti-fraud signal system), none of which replace what third-party cookies do for tracking and ad targeting.
The Actual Default Setting Right Now
Here’s the part worth checking for yourself rather than assuming: in 2026, Chrome keeps third-party cookies enabled by default, full stop. No automatic blocking happens on install or update. A Chrome user has to manually navigate to Privacy & Security settings and disable third-party cookies themselves; the browser will not do it for them, and there’s no prompt or notification encouraging that step. That’s a meaningfully different posture than what years of “Chrome is phasing out cookies” coverage led a lot of users to expect by now.
This Was Always Just a Chrome Story
It’s worth being precise about scope here, since the cookie phase-out conversation often got discussed as if it applied to “the internet” broadly rather than one specific browser. Safari has blocked third-party cookies by default since 2020, and goes further by enforcing a 7-day expiry on JavaScript-set first-party cookies specifically to limit workarounds. Firefox has partitioned all cookies by website since June 2022, meaning a tracker embedded across multiple sites can’t link activity between them even without an explicit block. Brave blocks third-party cookies and trackers by default as a core part of its positioning. Altogether, an estimated 17-20% of global web traffic already runs on a browser where this entire question is moot, and has been for years. Google’s reversal doesn’t change anything for that share of users; it only affects the roughly 80% of web traffic still running on Chrome by default.
Why This Matters More Than It Sounds
A third-party cookie is the specific mechanism that lets an advertiser or ad network recognize you across completely unrelated websites, building a profile of your browsing behavior that follows you from a shopping site to a news site to a completely unrelated forum, without you ever logging into any of them with the same account. That’s a meaningfully different, more persistent tracking capability than a first-party cookie a single site sets for its own login or shopping cart. If you assumed this was already handled because you vaguely remember reading Chrome was phasing cookies out, the practical reality is that your browsing profile has kept building exactly as it did before 2020, uninterrupted, unless you went in and changed the setting yourself at some point.
Why “User Choice” Framing Matters Here
Google’s own language, framing this as offering “third-party cookie choice” rather than announcing a default block, is worth reading carefully rather than glossing over as corporate phrasing. A genuine privacy default protects users who never think about the setting at all; a “choice” framing puts the burden specifically on the user to seek out and change a setting they may not know exists, understand the implications of, or think to look for. Safari, Firefox, and Brave’s approach, blocking by default and letting users opt back in if a specific site genuinely needs it, inverts that burden entirely. The practical difference between those two models isn’t philosophical; it’s the difference between a browser that protects a user who does nothing at all, and one that requires active, informed effort to get the same protection, which is exactly why the raw percentage of Chrome users still running default settings matters as much as the fact that the setting technically exists.
How to Actually Check and Change This
A few concrete steps, specific to Chrome since that’s the browser where this default actually matters:
- Go to Chrome Settings, then Privacy and Security, then Third-Party Cookies (the exact menu wording has shifted slightly across Chrome versions, but it’s consistently under the Privacy and Security section). Confirm whether it’s currently set to allow or block third-party cookies; don’t assume based on memory of a setting you may have changed years ago or never touched at all.
- If you want them blocked, switch the setting to “Block third-party cookies” directly rather than relying on any assumption that a browser update handled this automatically. It hasn’t, and per Google’s own April 2025 statement, it isn’t going to.
- Understand that blocking third-party cookies can occasionally break specific site functionality that legitimately depends on cross-site cookies, some embedded payment widgets or single-sign-on flows among them, which is part of why Google frames this as a user choice rather than a blanket default; it’s a real tradeoff, not a decision with no downside at all.
- If cross-browser consistency matters to you, know that switching to Firefox, Safari (on Apple devices), or Brave gets you the blocked-by-default behavior without needing to remember to configure it, since all three have shipped that as their standard behavior for multiple years already.
What Advertisers Are Doing Instead
With Privacy Sandbox’s core targeting APIs discontinued and third-party cookies staying on by default, the advertising industry’s practical response has largely been to keep relying on the exact tracking infrastructure Privacy Sandbox was meant to replace, rather than pivoting to a genuinely cookie-free targeting model. That’s a real, if somewhat circular, outcome: years of industry preparation for a cookie-free future led to a shutdown of the replacement technology and a default reversion to the status quo, which means the targeting and measurement tools advertisers use on Chrome specifically are largely unchanged from several years ago, cookie-based cross-site tracking included. For a user trying to understand why online ads still feel eerily specific to recent browsing across unrelated sites, the honest answer in 2026 is the same mechanism that’s been running the whole time, not some new post-cookie technology quietly taking over in the background.
The Bigger Pattern Worth Noticing
Google’s Privacy Sandbox shutdown is also worth reading as a real signal about how hard building a privacy-preserving alternative to cookie tracking turned out to be, at scale, for the company with arguably the most resources to attempt it. Low adoption of Topics, Protected Audience, and Attribution Reporting wasn’t a marketing failure; it reflected genuine friction in getting advertisers, publishers, and browser infrastructure all to adopt a fundamentally different targeting model at once. That’s a useful data point for treating “the industry is moving away from third-party cookies” as an ongoing, unresolved question rather than something already settled in either direction, regardless of which specific company’s roadmap gets covered next.
*Sources: Consenteo’s 2026 third-party cookie tracking analysis, cross-checked against Google’s own April 2025 announcement and October 2025 Privacy Sandbox shutdown notice.*
Photo credit: “PSP Web Browser” by wyzik, licensed BY (https://creativecommons.org/licenses/by/2.0/). Source: https://www.flickr.com/photos/54876474@N00/29250552


