vulns.co
/
GKData.io MCP

Google Chrome for Developers · 1 min read

Chrome bfcache: restored pages and session-state boundaries

Explains Chrome’s conditional admission of no-store pages to the back/forward cache. A restored page resumes in-memory document state rather than performing a fresh network load. The guide describes eviction safeguards around authentication changes and recommends considering data refresh on restoration.

Open the reference Implementation GuideReviewed 2026-10-03

How to use this reference

Distinguish HTTP cache policy from suspended-page lifetime in an owned application’s session model. Define how sensitive state is cleared or refreshed after restoration and how logout remains effective across navigation. Preserve server-side authorization independently of restored client state.

Before reading

  • Browser origin and navigation concepts
  • HTTP session and response-cache fundamentals

Context and limits

  • Chrome-specific eligibility safeguards must not be generalized to every browser or authentication design.
  • The broader web.dev guide still describes the Chrome change as ongoing; the separately dated Chrome article provides more specific implementation context.
  • No browser execution or live application assessment was performed; this is lifecycle guidance, not an individual vulnerability report.

Sources and provenance

  1. Enabling bfcache for Cache-Control: no-store Google Chrome for Developers · reviewed 2026-10-03
  2. Back/forward cache Google web.dev · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software