Security: squillo/wgpu

Security

SECURITY.md

wgpu Security Policy

This document describes what is considered a security vulnerability in wgpu and how vulnerabilities should be reported.

Vulnerability Definition

WebGPU introduces a different threat model than is sometimes applied to GPU-related software. Unlike typical gaming or high-performance computing applications, where the software accessing GPU APIs is proprietary or obtained from a trusted developer, WebGPU makes GPU APIs available to arbitrary web applications. In the threat model of the web, malicious content should not be able to use the GPU APIs to access data or interfaces outside the intended scope for interaction with web content. Therefore, wgpu seeks to prevent undefined behavior and data leaks even when its API is misused, and failures to do so may be considered vulnerabilities. (This is also in accordance with the Rust principle of safe vs. unsafe code, since the wgpu library exposes a safe API.)

The wgpu maintainers have discretion in assigning a severity to individual vulnerabilities. It is generally considered a high-severity vulnerability in wgpu if JavaScript or WebAssembly code, running with privileges of ordinary web content in a browser that is using wgpu to provide the WebGPU API to that content, is able to:

  • Access data associated with native applications other than the user agent, or associated with other web origins.
  • Escape the applicable sandbox and run arbitrary code or call arbitrary system APIs on the user agent host.
  • Consume system resources to the point that it is difficult to recover (e.g. by closing the web page).

The wgpu Rust API offers some functionality, both supported and experimental, that is not part of the WebGPU standard and is not made available in JavaScript environments using wgpu. Associated vulnerabilities may be assigned lower severity than vulnerabilities that apply to a wgpu-based WebGPU implementation exposed to JavaScript.

Supported Versions

The wgpu project maintains security support for serious vulnerabilities in the most recent major release. Fixes for security vulnerabilities found shortly after the initial release of a major version may also be provided for the previous major release.

Mozilla provides security support for versions of wgpu used in current versions of Firefox.

The version of wgpu that is active can be found in the Firefox repositories:

We welcome reports of security vulnerabilities in any of these released versions or in the latest code on the trunk branch.

Reporting a Vulnerability

Although not all vulnerabilities in wgpu will affect Firefox, Mozilla accepts all vulnerability reports for wgpu and directs them appropriately. Additionally, Mozilla serves as the CVE numbering authority for the wgpu project.

To report a security problem with wgpu, create a bug in Mozilla's Bugzilla instance in the Core :: Graphics :: WebGPU component.

IMPORTANT: For security issues, please make sure that you check the box labelled "Many users could be harmed by this security problem". We advise that you check this option for anything that is potentially security-relevant, including memory safety, crashes, race conditions, and handling of confidential information.

Review Mozilla's guides on bug reporting before you open a bug.

Mozilla operates a bug bounty program. Some vulnerabilities in this project may be eligible.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Security: squillo/wgpu

Security

SECURITY.md

wgpu Security Policy

This document describes what is considered a security vulnerability in wgpu and how vulnerabilities should be reported.

Vulnerability Definition

WebGPU introduces a different threat model than is sometimes applied to GPU-related software. Unlike typical gaming or high-performance computing applications, where the software accessing GPU APIs is proprietary or obtained from a trusted developer, WebGPU makes GPU APIs available to arbitrary web applications. In the threat model of the web, malicious content should not be able to use the GPU APIs to access data or interfaces outside the intended scope for interaction with web content. Therefore, wgpu seeks to prevent undefined behavior and data leaks even when its API is misused, and failures to do so may be considered vulnerabilities. (This is also in accordance with the Rust principle of safe vs. unsafe code, since the wgpu library exposes a safe API.)

The wgpu maintainers have discretion in assigning a severity to individual vulnerabilities. It is generally considered a high-severity vulnerability in wgpu if JavaScript or WebAssembly code, running with privileges of ordinary web content in a browser that is using wgpu to provide the WebGPU API to that content, is able to:

  • Access data associated with native applications other than the user agent, or associated with other web origins.
  • Escape the applicable sandbox and run arbitrary code or call arbitrary system APIs on the user agent host.
  • Consume system resources to the point that it is difficult to recover (e.g. by closing the web page).

The wgpu Rust API offers some functionality, both supported and experimental, that is not part of the WebGPU standard and is not made available in JavaScript environments using wgpu. Associated vulnerabilities may be assigned lower severity than vulnerabilities that apply to a wgpu-based WebGPU implementation exposed to JavaScript.

Supported Versions

The wgpu project maintains security support for serious vulnerabilities in the most recent major release. Fixes for security vulnerabilities found shortly after the initial release of a major version may also be provided for the previous major release.

Mozilla provides security support for versions of wgpu used in current versions of Firefox.

The version of wgpu that is active can be found in the Firefox repositories:

We welcome reports of security vulnerabilities in any of these released versions or in the latest code on the trunk branch.

Reporting a Vulnerability

Although not all vulnerabilities in wgpu will affect Firefox, Mozilla accepts all vulnerability reports for wgpu and directs them appropriately. Additionally, Mozilla serves as the CVE numbering authority for the wgpu project.

To report a security problem with wgpu, create a bug in Mozilla's Bugzilla instance in the Core :: Graphics :: WebGPU component.

IMPORTANT: For security issues, please make sure that you check the box labelled "Many users could be harmed by this security problem". We advise that you check this option for anything that is potentially security-relevant, including memory safety, crashes, race conditions, and handling of confidential information.

Review Mozilla's guides on bug reporting before you open a bug.

Mozilla operates a bug bounty program. Some vulnerabilities in this project may be eligible.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: squillo/wgpu

Security

SECURITY.md

wgpu Security Policy

This document describes what is considered a security vulnerability in wgpu and how vulnerabilities should be reported.

Vulnerability Definition

WebGPU introduces a different threat model than is sometimes applied to GPU-related software. Unlike typical gaming or high-performance computing applications, where the software accessing GPU APIs is proprietary or obtained from a trusted developer, WebGPU makes GPU APIs available to arbitrary web applications. In the threat model of the web, malicious content should not be able to use the GPU APIs to access data or interfaces outside the intended scope for interaction with web content. Therefore, wgpu seeks to prevent undefined behavior and data leaks even when its API is misused, and failures to do so may be considered vulnerabilities. (This is also in accordance with the Rust principle of safe vs. unsafe code, since the wgpu library exposes a safe API.)

The wgpu maintainers have discretion in assigning a severity to individual vulnerabilities. It is generally considered a high-severity vulnerability in wgpu if JavaScript or WebAssembly code, running with privileges of ordinary web content in a browser that is using wgpu to provide the WebGPU API to that content, is able to:

  • Access data associated with native applications other than the user agent, or associated with other web origins.
  • Escape the applicable sandbox and run arbitrary code or call arbitrary system APIs on the user agent host.
  • Consume system resources to the point that it is difficult to recover (e.g. by closing the web page).

The wgpu Rust API offers some functionality, both supported and experimental, that is not part of the WebGPU standard and is not made available in JavaScript environments using wgpu. Associated vulnerabilities may be assigned lower severity than vulnerabilities that apply to a wgpu-based WebGPU implementation exposed to JavaScript.

Supported Versions

The wgpu project maintains security support for serious vulnerabilities in the most recent major release. Fixes for security vulnerabilities found shortly after the initial release of a major version may also be provided for the previous major release.

Mozilla provides security support for versions of wgpu used in current versions of Firefox.

The version of wgpu that is active can be found in the Firefox repositories:

We welcome reports of security vulnerabilities in any of these released versions or in the latest code on the trunk branch.

Reporting a Vulnerability

Although not all vulnerabilities in wgpu will affect Firefox, Mozilla accepts all vulnerability reports for wgpu and directs them appropriately. Additionally, Mozilla serves as the CVE numbering authority for the wgpu project.

To report a security problem with wgpu, create a bug in Mozilla's Bugzilla instance in the Core :: Graphics :: WebGPU component.

IMPORTANT: For security issues, please make sure that you check the box labelled "Many users could be harmed by this security problem". We advise that you check this option for anything that is potentially security-relevant, including memory safety, crashes, race conditions, and handling of confidential information.

Review Mozilla's guides on bug reporting before you open a bug.

Mozilla operates a bug bounty program. Some vulnerabilities in this project may be eligible.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: squillo/wgpu

Security

SECURITY.md

wgpu Security Policy

This document describes what is considered a security vulnerability in wgpu and how vulnerabilities should be reported.

Vulnerability Definition

WebGPU introduces a different threat model than is sometimes applied to GPU-related software. Unlike typical gaming or high-performance computing applications, where the software accessing GPU APIs is proprietary or obtained from a trusted developer, WebGPU makes GPU APIs available to arbitrary web applications. In the threat model of the web, malicious content should not be able to use the GPU APIs to access data or interfaces outside the intended scope for interaction with web content. Therefore, wgpu seeks to prevent undefined behavior and data leaks even when its API is misused, and failures to do so may be considered vulnerabilities. (This is also in accordance with the Rust principle of safe vs. unsafe code, since the wgpu library exposes a safe API.)

The wgpu maintainers have discretion in assigning a severity to individual vulnerabilities. It is generally considered a high-severity vulnerability in wgpu if JavaScript or WebAssembly code, running with privileges of ordinary web content in a browser that is using wgpu to provide the WebGPU API to that content, is able to:

  • Access data associated with native applications other than the user agent, or associated with other web origins.
  • Escape the applicable sandbox and run arbitrary code or call arbitrary system APIs on the user agent host.
  • Consume system resources to the point that it is difficult to recover (e.g. by closing the web page).

The wgpu Rust API offers some functionality, both supported and experimental, that is not part of the WebGPU standard and is not made available in JavaScript environments using wgpu. Associated vulnerabilities may be assigned lower severity than vulnerabilities that apply to a wgpu-based WebGPU implementation exposed to JavaScript.

Supported Versions

The wgpu project maintains security support for serious vulnerabilities in the most recent major release. Fixes for security vulnerabilities found shortly after the initial release of a major version may also be provided for the previous major release.

Mozilla provides security support for versions of wgpu used in current versions of Firefox.

The version of wgpu that is active can be found in the Firefox repositories:

We welcome reports of security vulnerabilities in any of these released versions or in the latest code on the trunk branch.

Reporting a Vulnerability

Although not all vulnerabilities in wgpu will affect Firefox, Mozilla accepts all vulnerability reports for wgpu and directs them appropriately. Additionally, Mozilla serves as the CVE numbering authority for the wgpu project.

To report a security problem with wgpu, create a bug in Mozilla's Bugzilla instance in the Core :: Graphics :: WebGPU component.

IMPORTANT: For security issues, please make sure that you check the box labelled "Many users could be harmed by this security problem". We advise that you check this option for anything that is potentially security-relevant, including memory safety, crashes, race conditions, and handling of confidential information.

Review Mozilla's guides on bug reporting before you open a bug.

Mozilla operates a bug bounty program. Some vulnerabilities in this project may be eligible.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Security: squillo/wgpu

Security

SECURITY.md

wgpu Security Policy

This document describes what is considered a security vulnerability in wgpu and how vulnerabilities should be reported.

Vulnerability Definition

WebGPU introduces a different threat model than is sometimes applied to GPU-related software. Unlike typical gaming or high-performance computing applications, where the software accessing GPU APIs is proprietary or obtained from a trusted developer, WebGPU makes GPU APIs available to arbitrary web applications. In the threat model of the web, malicious content should not be able to use the GPU APIs to access data or interfaces outside the intended scope for interaction with web content. Therefore, wgpu seeks to prevent undefined behavior and data leaks even when its API is misused, and failures to do so may be considered vulnerabilities. (This is also in accordance with the Rust principle of safe vs. unsafe code, since the wgpu library exposes a safe API.)

The wgpu maintainers have discretion in assigning a severity to individual vulnerabilities. It is generally considered a high-severity vulnerability in wgpu if JavaScript or WebAssembly code, running with privileges of ordinary web content in a browser that is using wgpu to provide the WebGPU API to that content, is able to:

  • Access data associated with native applications other than the user agent, or associated with other web origins.
  • Escape the applicable sandbox and run arbitrary code or call arbitrary system APIs on the user agent host.
  • Consume system resources to the point that it is difficult to recover (e.g. by closing the web page).

The wgpu Rust API offers some functionality, both supported and experimental, that is not part of the WebGPU standard and is not made available in JavaScript environments using wgpu. Associated vulnerabilities may be assigned lower severity than vulnerabilities that apply to a wgpu-based WebGPU implementation exposed to JavaScript.

Supported Versions

The wgpu project maintains security support for serious vulnerabilities in the most recent major release. Fixes for security vulnerabilities found shortly after the initial release of a major version may also be provided for the previous major release.

Mozilla provides security support for versions of wgpu used in current versions of Firefox.

The version of wgpu that is active can be found in the Firefox repositories:

We welcome reports of security vulnerabilities in any of these released versions or in the latest code on the trunk branch.

Reporting a Vulnerability

Although not all vulnerabilities in wgpu will affect Firefox, Mozilla accepts all vulnerability reports for wgpu and directs them appropriately. Additionally, Mozilla serves as the CVE numbering authority for the wgpu project.

To report a security problem with wgpu, create a bug in Mozilla's Bugzilla instance in the Core :: Graphics :: WebGPU component.

IMPORTANT: For security issues, please make sure that you check the box labelled "Many users could be harmed by this security problem". We advise that you check this option for anything that is potentially security-relevant, including memory safety, crashes, race conditions, and handling of confidential information.

Review Mozilla's guides on bug reporting before you open a bug.

Mozilla operates a bug bounty program. Some vulnerabilities in this project may be eligible.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: squillo/wgpu

Security

SECURITY.md

wgpu Security Policy

This document describes what is considered a security vulnerability in wgpu and how vulnerabilities should be reported.

Vulnerability Definition

WebGPU introduces a different threat model than is sometimes applied to GPU-related software. Unlike typical gaming or high-performance computing applications, where the software accessing GPU APIs is proprietary or obtained from a trusted developer, WebGPU makes GPU APIs available to arbitrary web applications. In the threat model of the web, malicious content should not be able to use the GPU APIs to access data or interfaces outside the intended scope for interaction with web content. Therefore, wgpu seeks to prevent undefined behavior and data leaks even when its API is misused, and failures to do so may be considered vulnerabilities. (This is also in accordance with the Rust principle of safe vs. unsafe code, since the wgpu library exposes a safe API.)

The wgpu maintainers have discretion in assigning a severity to individual vulnerabilities. It is generally considered a high-severity vulnerability in wgpu if JavaScript or WebAssembly code, running with privileges of ordinary web content in a browser that is using wgpu to provide the WebGPU API to that content, is able to:

  • Access data associated with native applications other than the user agent, or associated with other web origins.
  • Escape the applicable sandbox and run arbitrary code or call arbitrary system APIs on the user agent host.
  • Consume system resources to the point that it is difficult to recover (e.g. by closing the web page).

The wgpu Rust API offers some functionality, both supported and experimental, that is not part of the WebGPU standard and is not made available in JavaScript environments using wgpu. Associated vulnerabilities may be assigned lower severity than vulnerabilities that apply to a wgpu-based WebGPU implementation exposed to JavaScript.

Supported Versions

The wgpu project maintains security support for serious vulnerabilities in the most recent major release. Fixes for security vulnerabilities found shortly after the initial release of a major version may also be provided for the previous major release.

Mozilla provides security support for versions of wgpu used in current versions of Firefox.

The version of wgpu that is active can be found in the Firefox repositories:

We welcome reports of security vulnerabilities in any of these released versions or in the latest code on the trunk branch.

Reporting a Vulnerability

Although not all vulnerabilities in wgpu will affect Firefox, Mozilla accepts all vulnerability reports for wgpu and directs them appropriately. Additionally, Mozilla serves as the CVE numbering authority for the wgpu project.

To report a security problem with wgpu, create a bug in Mozilla's Bugzilla instance in the Core :: Graphics :: WebGPU component.

IMPORTANT: For security issues, please make sure that you check the box labelled "Many users could be harmed by this security problem". We advise that you check this option for anything that is potentially security-relevant, including memory safety, crashes, race conditions, and handling of confidential information.

Review Mozilla's guides on bug reporting before you open a bug.

Mozilla operates a bug bounty program. Some vulnerabilities in this project may be eligible.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: squillo/wgpu

Security

SECURITY.md

wgpu Security Policy

This document describes what is considered a security vulnerability in wgpu and how vulnerabilities should be reported.

Vulnerability Definition

WebGPU introduces a different threat model than is sometimes applied to GPU-related software. Unlike typical gaming or high-performance computing applications, where the software accessing GPU APIs is proprietary or obtained from a trusted developer, WebGPU makes GPU APIs available to arbitrary web applications. In the threat model of the web, malicious content should not be able to use the GPU APIs to access data or interfaces outside the intended scope for interaction with web content. Therefore, wgpu seeks to prevent undefined behavior and data leaks even when its API is misused, and failures to do so may be considered vulnerabilities. (This is also in accordance with the Rust principle of safe vs. unsafe code, since the wgpu library exposes a safe API.)

The wgpu maintainers have discretion in assigning a severity to individual vulnerabilities. It is generally considered a high-severity vulnerability in wgpu if JavaScript or WebAssembly code, running with privileges of ordinary web content in a browser that is using wgpu to provide the WebGPU API to that content, is able to:

  • Access data associated with native applications other than the user agent, or associated with other web origins.
  • Escape the applicable sandbox and run arbitrary code or call arbitrary system APIs on the user agent host.
  • Consume system resources to the point that it is difficult to recover (e.g. by closing the web page).

The wgpu Rust API offers some functionality, both supported and experimental, that is not part of the WebGPU standard and is not made available in JavaScript environments using wgpu. Associated vulnerabilities may be assigned lower severity than vulnerabilities that apply to a wgpu-based WebGPU implementation exposed to JavaScript.

Supported Versions

The wgpu project maintains security support for serious vulnerabilities in the most recent major release. Fixes for security vulnerabilities found shortly after the initial release of a major version may also be provided for the previous major release.

Mozilla provides security support for versions of wgpu used in current versions of Firefox.

The version of wgpu that is active can be found in the Firefox repositories:

We welcome reports of security vulnerabilities in any of these released versions or in the latest code on the trunk branch.

Reporting a Vulnerability

Although not all vulnerabilities in wgpu will affect Firefox, Mozilla accepts all vulnerability reports for wgpu and directs them appropriately. Additionally, Mozilla serves as the CVE numbering authority for the wgpu project.

To report a security problem with wgpu, create a bug in Mozilla's Bugzilla instance in the Core :: Graphics :: WebGPU component.

IMPORTANT: For security issues, please make sure that you check the box labelled "Many users could be harmed by this security problem". We advise that you check this option for anything that is potentially security-relevant, including memory safety, crashes, race conditions, and handling of confidential information.

Review Mozilla's guides on bug reporting before you open a bug.

Mozilla operates a bug bounty program. Some vulnerabilities in this project may be eligible.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Security: squillo/wgpu

Security

SECURITY.md

wgpu Security Policy

This document describes what is considered a security vulnerability in wgpu and how vulnerabilities should be reported.

Vulnerability Definition

WebGPU introduces a different threat model than is sometimes applied to GPU-related software. Unlike typical gaming or high-performance computing applications, where the software accessing GPU APIs is proprietary or obtained from a trusted developer, WebGPU makes GPU APIs available to arbitrary web applications. In the threat model of the web, malicious content should not be able to use the GPU APIs to access data or interfaces outside the intended scope for interaction with web content. Therefore, wgpu seeks to prevent undefined behavior and data leaks even when its API is misused, and failures to do so may be considered vulnerabilities. (This is also in accordance with the Rust principle of safe vs. unsafe code, since the wgpu library exposes a safe API.)

The wgpu maintainers have discretion in assigning a severity to individual vulnerabilities. It is generally considered a high-severity vulnerability in wgpu if JavaScript or WebAssembly code, running with privileges of ordinary web content in a browser that is using wgpu to provide the WebGPU API to that content, is able to:

  • Access data associated with native applications other than the user agent, or associated with other web origins.
  • Escape the applicable sandbox and run arbitrary code or call arbitrary system APIs on the user agent host.
  • Consume system resources to the point that it is difficult to recover (e.g. by closing the web page).

The wgpu Rust API offers some functionality, both supported and experimental, that is not part of the WebGPU standard and is not made available in JavaScript environments using wgpu. Associated vulnerabilities may be assigned lower severity than vulnerabilities that apply to a wgpu-based WebGPU implementation exposed to JavaScript.

Supported Versions

The wgpu project maintains security support for serious vulnerabilities in the most recent major release. Fixes for security vulnerabilities found shortly after the initial release of a major version may also be provided for the previous major release.

Mozilla provides security support for versions of wgpu used in current versions of Firefox.

The version of wgpu that is active can be found in the Firefox repositories:

We welcome reports of security vulnerabilities in any of these released versions or in the latest code on the trunk branch.

Reporting a Vulnerability

Although not all vulnerabilities in wgpu will affect Firefox, Mozilla accepts all vulnerability reports for wgpu and directs them appropriately. Additionally, Mozilla serves as the CVE numbering authority for the wgpu project.

To report a security problem with wgpu, create a bug in Mozilla's Bugzilla instance in the Core :: Graphics :: WebGPU component.

IMPORTANT: For security issues, please make sure that you check the box labelled "Many users could be harmed by this security problem". We advise that you check this option for anything that is potentially security-relevant, including memory safety, crashes, race conditions, and handling of confidential information.

Review Mozilla's guides on bug reporting before you open a bug.

Mozilla operates a bug bounty program. Some vulnerabilities in this project may be eligible.

There aren't any published security advisories