Vickie Li·FollowDec 15, 2020--ListenShareThanks for reading! No, HttpOnly does not prevent or mitigate CSRF attacks. They do help mitigate XSS attacks though because attacker scripts cannot read or exfiltrate the cookies protected by HttpOnly.