The `X-Content-Type-Options: nosniff` header allows a server to assert that its resources may only be executed as script or applied as style if they're delivered with appropriate `Content-Type` headers.
Status in Chromium
Enabled by default (tracking bug) in:
- Chrome for desktop release 64
- Chrome for Android release 64
- Android WebView release 64
Consensus & Standardization
Last updated on 2020-11-09