
Yes, WebGL has been a successful attack vector in cases like CVE-2021-30554 (Chrome WebGL use-after-free), listed in CISA's Known Exploited Vulnerabilities for in-the-wild RCE via malicious pages. Cryptojacking malware also routinely abuses it for GPU theft. Microsoft's 2011 concerns ("WebGL Considered Harmful") had basis: it exposes GPU/drivers (often unpatched OEM ones) to untrusted web code, enabling DoS, driver exploits, and info leaks per early ContextIS research. Browsers mitigated via blacklists, same-origin restrictions, and sandboxing, but CVEs keep coming. Not an internet-destroying threat, but a real added surface that's been exploited.
Post summary
The post underscores that WebGL vulnerabilities such as CVE‑2021‑30554 have been actively exploited in the wild, highlighting RCE and cryptojacking incidents without providing new patch or PoC details.
