Would be interesting to turn it around and have the browser assign + send a unique ID per domain, server then stores what it needs server-side based on ID. User can rotate as desired. It’s essentially the iOS notion of advertising ID.
If you wonder why some attacks are not eligible for a bug bounty, here's a good read about why physical attacks are outside the threat model for Chrome.
chromium.googlesource.com/ch…