ERR_BLOCKED_BY_CLIENT, _RESPONSE and _ORB: which one you have

Chrome's Network tab and console show a request as (blocked:…) or net::ERR_BLOCKED_BY_…. The last word matters: it tells you whether your browser, the server or Chrome's own safety check stopped the request.

ErrorWho blocked itUsual cause
ERR_BLOCKED_BY_CLIENTYour browser, before sendingAd blocker or privacy extension
ERR_BLOCKED_BY_RESPONSEThe server's response headersFraming rules, Cross-Origin-Resource-Policy, COEP
ERR_BLOCKED_BY_ORBChrome, after receivingThe URL returned HTML, JSON or the wrong type

net::ERR_BLOCKED_BY_CLIENT

"Client" means your browser. An extension, nearly always an ad or tracker blocker (uBlock Origin, AdBlock, Privacy Badger, Ghostery, Brave Shields), cancelled the request before it left. The server never saw it.

net::ERR_BLOCKED_BY_RESPONSE

The server responded, but its headers say this page may not use the response this way. The part after the dot tells you which rule:

You seeHeader responsibleFix (on the server that sent it)
In an iframe, often with "refused to connect"X-Frame-Options or CSP frame-ancestorsAllow your site in frame-ancestors. Details.
.NotSameOrigin / .NotSameSiteCross-Origin-Resource-Policy: same-origin or same-siteSend Cross-Origin-Resource-Policy: cross-origin on files meant to be embedded elsewhere
.NotSameOriginAfterDefaultedToSameOriginByCoepYour page sends Cross-Origin-Embedder-Policy: require-corpThe other server must send CORP cross-origin, or load it with crossorigin plus CORS, or use COEP: credentialless

If the file isn't yours, you can't fix it for your visitors; copy it to your own server if its licence allows. Pages using COEP usually do so for SharedArrayBuffer; if you don't need that, dropping COEP makes the error disappear.

net::ERR_BLOCKED_BY_ORB

Opaque Response Blocking is Chrome's protection against pages using <img>, <script> or <video> tags to pull private data from other sites. When a cross-origin response loaded that way doesn't look like the image, script or media the tag expects, Chrome throws it away. In practice, the URL is wrong:

Check: open the URL in its own tab and look at what comes back and its Content-Type in the Network tab. Fix the URL, or on your own server send the correct Content-Type together with X-Content-Type-Options: nosniff; without nosniff, Chrome guesses the type from the first bytes, and that guess is what blocks some legitimate files. If you're fetching data, use fetch() with CORS instead of a tag.

Testing header fixes before the server changes

For ERR_BLOCKED_BY_RESPONSE, you can check that a header change fixes it by changing the header in your own browser first, then asking whoever runs the server for the real fix.

HeaderForge (Chrome, free)

Remove X-Frame-Options or Cross-Origin-Resource-Policy from a site's responses, or set CORP to cross-origin, only on the sites you choose, and see whether each rule fired. No account, no tracking.

Get HeaderForge for Chrome

More on this topic: CORS tester · CORS error: what it means and how to fix it (including localhost) · “Has been blocked by CORS policy”: every variant and its fix · Access-Control-Allow-Origin: values, multiple origins and server examples