WebGL Information disclosure through OS X NVIDIA graphic drivers

Related Vulnerabilities: CVE-2013-1729  

Mozilla Foundation Security Advisory 2013-86

WebGL Information disclosure through OS X NVIDIA graphic drivers

Announced
September 17, 2013
Reporter
Victor Porof
Impact
Moderate
Products
Firefox
Fixed in
  • Firefox 24

Description

Mozilla developer Victor Porof reported a flaw in the NVIDIA OS X graphic drivers that would allow portions of a user's desktop or other visible applications to be incorporated into WebGL canvases. This could result in personal information becoming available to web content.

References