The Java browser plugin sees a codebase URL of the target site and consequently adds a allowing the applet to connect back to it and make full requests.
It turns out that when an applet makes an HTTP request to a website the Java browser plugin will slap on the relevant cookies from the browser cookie store (even if the applet is unsigned).