WebGL flaws hit Firefox and Chrome
By Tom Brewster,
Web users have been told to turn off the WebGL 3D rendering engine in Firefox 4 and Google Chrome due to security issues.
The US Computer Emergency Readiness Team (US-CERT) recommended users turn off WebGL, designed to display 3D graphics in browsers on any machine, after Context Information Security found problems in the rendering tool.
The flaws could hand hackers low level access to graphics cards, potentially providing a back door for cyber criminals looking to get their hands on user data.
If a user visited a site with malicious WebGL script, the WebGL component would then upload a specified 3D code to the end user’s graphics card, Context said in a blog post.
The code could then exploit flaws in unpatched graphics drivers, meaning the GPU could be attacked causing a machine to completely shut down.
Context said one of the central issues was that WebGL provides access to the graphics hardware. In comparison, with 2D graphic acceleration, the actual functionality of the GPU is not directly exposed to a webpage.
Therefore WebGL could allow for the creation of shader programs designed to suck up the targeted computer’s power, effectively carrying out a denial of service attack and preventing the user from accessing their machine, according to Context.
“The risks stem from the fact that most graphics cards and drivers have not been written with security in mind so that the interface (API) they expose assumes that the applications are trusted,” said Michael Jordon, research and development manager at Context.
“While this may be true for local applications, the use of WebGL-enabled browser-based applications with certain graphics cards now poses serious threats from breaking the cross domain security principle to denial of service attacks, potentially leading to full exploitation of a user’s machine.”
WebGL, which can be switched on in Apple’s Safari browser as well, is becoming more widely used in modern smartphones, the security firm noted.
“We think it is important to raise awareness of this issue before WebGL becomes more widely adopted because this is not an implementation problem, but is down largely to the WebGL specification, which is inherently insecure,” Jordon added.
Context said the problems were “inherent to the WebGL specification and would require significant architectural changes in order to remediate in the platform design.”
The Khronos Group, which officially released WebGL 1.0 in March, defended the security credentials of the standard.
“The WebGL specification was developed with security concerns in mind from day one, and the WebGL working group has been working closely with the GPU vendors in the Khronos group on WebGL security,” the Khronos Group said in a website posting.
“The Khronos group has already specified one extension to OpenGL, GL_ARB_robustness, specifically designed to prevent denial of service and out-of-range memory access attacks from WebGL content, and is continuing to rapidly iterate on security-related functionality.”
You may also like...
Sponsored Links
advertisement
You may also like...
Latest Security Analysis & Insight
What is your password worth?
Would you be tempted to sell off company passwords for a fee? If not, seems like you're in the minority, acccording to research.
- Macs under attack?
- Intel: security inside
- Are you spending too much on IT security?
- Does the government want to snoop on your data?
- Eurocrats versus the cyber criminals
- The truth about spam
- Google and privacy: What’s the problem?
- Q&A: Symantec’s CISO on the source code hack
- RSA: Back from the breach?
Latest Security Reviews
Check Point 2210 Appliance review
Rating: ![]()
advertisement
Most popular
- UK regulator shuts down Angry Birds scam
- Apple iPad 3 vs iPad 2 head-to-head review
- IBM bans use of Siri on iPhones
- Chromebooks: What's gone wrong?
- HP plans massive job cuts
- EMC World 2012: Tucci declares Documentum is here to stay
- Dell EqualLogic PS6100XS review
- Macs and Android under malware threat
- RIM loses its head of sales
- Local fibre broadband needs common standards
Latest News Videos in Security
IT PRO Podcast: Are UK data protection laws flawed?
We bring in two experts to talk about the problems with UK data protection law and the way it is managed.
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.





