edit: tried it on chromium 66: doesn't work.
steps to reproduce:
1. open new (non-private) tab, go to http://httpbin.org/cookies/set?k1=v1&k2=v2
2. check http://httpbin.org/cookies/, the two cookies should be there, and if you check the dev console, the expiry date is 1970-01-01 - 1 second. firefox says it's "until end of session".
3. open new private tab, go to http://httpbin.org/cookies
4. cookies from above do not show up.
Here's what Google says about cookies in incognito mode: "If you use Chrome in incognito mode (or in guest mode on Chrome OS), it will not transmit any pre-existing cookies to sites that you visit. Sites may deposit new cookies on your system while you are in these modes; these cookies will only be temporarily stored and transmitted to sites while you remain in incognito / guest mode. They will be deleted when you close the browser, close all open incognito windows or exit guest mode." Source: https://www.google.com/chrome/browser/privacy/archive/201408...
I first noticed that FB might be able to detect sites you visit while in incognito mode when I noticed that I was personally being retargeted by sites I visited in incognito mode while on Facebook. Here's an interesting quora thread I found while looking into it: "Also the cookies act too important role here. Cookies during Incognito Mode are saved in temporary folder, and they get purged after session ends. But when browsing Facebook and Google in the same session, they both share same cookies folder and cookies help to send tailored ads to users." https://www.quora.com/Im-using-Incognito-mode-for-Google-sea...
Curious for your take.
To be clear, the claim I'm making is that normal windows can read cookies from incognito windows.
There are potential information leaks, such as the combination of IP address, user agent, screen size, and fonts available. And there may be bugs in 3rd party plugins like Flash that fail to respect private mode. But it doesn't seem to be anything as simple as cookies being shared.