Shouldn't a browser not send cookies when the request comes from a different domain? That would seem like the most sensible solution to me. Unless somebody can show a caveat of course.
[0] https://en.wikipedia.org/wiki/Cross-site_scripting
[1] (This is not my area of expertise. If I'm not correct... please let me know!)