WebGL standard riddled with security vulnerabilities?

updated 03:25 pm EDT, Tue May 10, 2011

Standard blasted by security researchers


Security research firm Context has issued a report criticizing WebGL, the 3D graphics standard used in popular browsers such as Firefox, Chrome and Safari. The report points to several serious vulnerabilities that are said to leave systems open to attacks. Experimental exploits reportedly used malicious code to gain access to a computer's core operating system.

These issues are inherent to the WebGL specification and would require significant architectural changes in order to remediate in the platform design," Context's James Forshaw wrote in a blog post. "Fundamentally, WebGL now allows full (Turing Complete) programs from the internet to reach the graphics driver and graphics hardware which operate in what is supposed to be the most protected part of the computer (Kernel Mode)."

Forshaw suggests that WebGL is not "ready for mass usage," and users should consider disabling the standard in browsers. The research firm points out that Firefox 4 and Chrome enable WebGL by default, while Safari leaves it as an option that can be turned on if needed.

The Khronos Group, an industry consortium that oversees WebGL development, responded to Context's criticisms, claiming that the standard had already been improved to protect against some of the vulnerabilities. The group placed part of the blame on graphics card manufacturers for not releasing updated drivers to help protect systems.


By Electronista Staff

Other Articles

toggle

Previous Comments

  1. B9bot

    Fresh-Faced Recruit

    Joined: Dec 2008

    0

    I don't see an option in Safari to turn on WEBgl

    I've looked through all of the options in Safari preferences and there is no option for WEBgl.


  1. Integr8d

    Fresh-Faced Recruit

    Joined: Apr 2010

    -5

    No Safari WebGL...

    Because Apple hasn't figured out how to repackage it into something 'magical'.


Login Here

Not a member of the MacNN forums? Register now for free.

 
close
Photo
toggle

Network Headlines

toggle

Most Popular

10 Most Read

Recent Reviews

iHome iW2 AirPlay speaker

iHome generally isn't known as a luxury brand when it comes to audio, but it is prolific -- the company's docks and speakers are every ...

Logitech Ultrathin Keyboard Cover

One of the iPad's main weaknesses has always been productivity. It's not a question of apps; while it has taken a little time for a na ...

Logitech UE Air Speaker

If maybe a little more slowly than Apple would like, AirPlay is becoming a staple of the wireless speaker market for iOS devices. The ...

toggle

Most Commented

10 Most Discussed

 
toggle

Popular News