Web Hack List

Collected research

Using Cross-domain images in WebGL and Chrome 13

After shaders were shown to leak the contents of GPU textures, the WebGL spec was tightened so Chrome 13 and Firefox 5 reject cross-domain media as textures, raising DOM_SECURITY_ERR. A new .crossOrigin attribute lets a site opt back in via CORS. With it set, a remote image no longer dirties the canvas origin-clean flag, so toDataURL and getImageData succeed.

Record

Researcher
Eric Bidelman
Published by
Chromium Blog
Topic
Browser

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Eric Bidelman, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .