> It's a self correcting problem. You go to a site, it freezes your machine, you never visit the site again.
What do regular users do about a malicious ad that runs on thousands of different sites?
> Turning off WebGL = no more Figma, no more Canva, no more Google Maps
Which is why you should probably rather turn off the actual vulnerable API, i.e. WebGPU, not WebGL.
It really ought to be something you can enable or disable per site. I was surprised to find its not.
Maybe a browser extension could inject JS in a tab to redefine all the WebGPU API into a noop.
I just don’t think people are doing malicious ads like that. Like I’m sure it exists but like what’s the point? If you are the malicious person you pay money for ads to freeze someone’s computer and that’s it? It’s not even like you would gain anything from it