> I'm not 100% sure on how the browsers implementation differs with CSP but there is a main difference in that there seems to be no CSP protected between Google domains in Google Chrome If this is true, does this mean that Google is short-cutting internet-security for their own applications in their own browser? Or am I reading this all wrong?
That's the way I read it too and I'm surprised no one else has mentioned this. Unless I'm missing something Google is allowing XSS for their own domains in chrome.
for example, even when using open source web kit or chromium they actively removed all options to disable referrer.
go on. try to find it on your current chrome build. or even on chromium thanks to their legacy.
then remember that referrer with its most exposing setting is required for Google to monetize both their organic and paid search.