Yeah, this is just standard third-party cookie functionality, which has always been sketchy. It honestly seems like it was only possible by accident; browsers have long prevented sites from reading cookies from other domains, but it seems like the people working on early specs might not have considered the ramifications of being able to set cookies for domains other than your own. A couple decades ago it might have seemed like no one would have any reason to set a cookie they couldn't read.