This doesn't seem to protect from Pass the Cookie attacks.
Edit - it's a common red teaming tactic: https://wunderwuzzi23.github.io/blog/passthecookie.html
Edit - it's a common red teaming tactic: https://wunderwuzzi23.github.io/blog/passthecookie.html
Section 7.2.3 talks about cookie theft.