Problem: If a browser has cached Bitcoin Core RPC credentials, another page permitted to reach RPC may be able to invoke methods using them. The calls can execute even when the page cannot read the response.
Browser RPC examples I found: Block Clock, transaction broadcasting.
Fix: Reject browser-origin RPC requests before authentication.
Note that this rejects every Origin value, including same-origin requests, null, and empty values. Browser or reverse-proxy integrations that add this header will need to adapt.