Any web page can ask your browser for the name of your graphics card. No permission prompt, no cookie banner, a few lines of JavaScript. On a typical Windows laptop the answer is something like ANGLE (NVIDIA, NVIDIA GeForce RTX 3060 (0x00002503) Direct3D11 vs_5_0 ps_5_0, D3D11), and the widget on this page shows you what yours says.
That is WebGL fingerprinting, and it is why fingerprint checkers print lines like “WebGL fingerprinting is present” or, more alarming, “WebGL renderer info is spoofed”. The first one is true of almost every browser on earth. The second means your browser got caught contradicting itself, usually because of an extension you installed.
What a WebGL fingerprint test reads from your browser
WebGL is the browser API for drawing 3D graphics with your GPU. It powers Google Maps, browser games and 3D product configurators, and to do that job it has to talk to real hardware. A fingerprinting script uses it in two ways.
It asks. The WEBGL_debug_renderer_info extension adds two constants, UNMASKED_VENDOR_WEBGL and UNMASKED_RENDERER_WEBGL. The name oversells it: the extension unmasks nothing, it just returns the driver’s GPU name instead of a placeholder like “WebKit WebGL”. Next to it sit dozens of capability values, the maximum texture size, supported extensions, shader precision, which differ between GPU families and driver versions. Together they are cheap to read and stable for months.
It watches. The script draws a small scene off-screen, reads the pixels back with readPixels, and hashes them. Different GPUs and drivers round colors, blend edges and evaluate shader math in slightly different ways, so the hash differs too. This is the same idea as canvas fingerprinting, one layer closer to the hardware.
People picture the name as something vague like “Intel graphics”. The real string reads like a spec sheet:
- ANGLE: the layer that turns WebGL into Direct3D, Metal or OpenGL calls. Chrome draws through it on every desktop OS, Firefox only on Windows; this exact format is Chrome’s.
- GPU maker
- The exact graphics chip, which also hints at how expensive the machine is
- PCI device ID: tells apart chip variants sold under the same name
- Direct3D: only exists on Windows
Direct3D only exists on Windows and Metal only on Apple hardware, so on most machines the GPU string settles the operating system question on its own, whatever your User-Agent says. It is the same cross-check we walked through in One Browser, Five OS Claims.
How unique is a WebGL fingerprint?
On its own, less than you might fear. Millions of people own an RTX 3060, and every M2 MacBook reports the same string. WebGL narrows you down to a hardware bucket, and a fingerprint is built by stacking buckets. An RTX 3060 is common. An RTX 3060 on a 1440p screen, in the Amsterdam time zone, with Dutch and English set as languages, is a small crowd.
Its value to trackers is persistence: you can switch browsers and clear every cookie, and your GPU stays the same. Researchers have pushed further. The 2022 DrawnApart study timed tiny workloads across a GPU’s execution units and could tell apart machines with identical hardware and identical renderer strings.
“WebGL fingerprinting is present” is not a warning
When a checker says WebGL fingerprinting is present, it means one thing: WebGL is switched on and readable. That is the normal state of every mainstream browser on every desktop and phone. It is not a sign that anything is wrong, and WebGL is not something you need to protect yourself from: the privacy cost is the fingerprint, and the fingerprint is what the rest of this page is about.
The tempting fix is to turn WebGL off. Don’t. Turning it off swaps a GPU you share with millions for a trait almost nobody has, and it breaks every site that draws with the GPU. A browser that refuses a standard API is also the kind of oddity that earns you extra CAPTCHAs.
Why a checker says “WebGL renderer info is spoofed”
The line most often shows up in Cloudflare Turnstile’s troubleshooter, under a check called “Graphics Information Appears Fake”, which people tend to find after a challenge keeps looping instead of letting them through. Nobody can see your GPU directly, so a checker cannot prove what hardware you have. What it can do is compare the claims against each other, and faked values rarely survive that. These are the tests. The widget on this page runs the first four:
- The graphics API does not fit the OS. A renderer string with Metal in it, sent by a browser whose User-Agent says Windows.
- Vendor and renderer disagree. The vendor field still says NVIDIA because the spoof only rewrote the renderer.
- The WebGL functions are patched. To change what
getParameterreturns, an extension has to replace it, and a naively replaced built-in stops reporting[native code]. Better-hidden patches need subtler checks. The same trap catches automation tools in our bot detection test. - The pixels change between reads. In practice a real GPU returns identical pixels when it draws the same scene twice. Some anti-fingerprinting extensions inject fresh random noise on every read, so two draws give two hashes. That instability is rarer than any GPU on the market.
- The name does not match the pixels. Anti-fraud vendors can compare your render output against what known devices produce. Claim an RTX 3060 while drawing like integrated Intel graphics and the render hash gives you away. A single browser cannot run this check, so the widget skips it.
Flip between the setups to see which tells each one trips:
ANGLE (Apple, ANGLE Metal Renderer: Apple M2, Unspecified Version)- Graphics API fits the OSMetal on a Windows User-Agent
- Vendor matches renderervendor still says NVIDIA
- WebGL functions are nativegetParameter was replaced
- Same drawing, same pixelstwo draws, one hash
In both spoofed setups the GPU is fine; every flag comes from the spoofing. If you got the “spoofed” warning without ever trying to spoof anything, check your extension list for a WebGL or canvas “defender”. That is the usual culprit, and Cloudflare’s troubleshooter names one, WebGL Fingerprint Defender, outright.
When the warning is a false alarm
Not every flag means someone tampered with your browser. A few ordinary setups trip checkers too:
- Remote desktop and virtual machines. With no real GPU available, the browser falls back to a software renderer such as llvmpipe or Microsoft’s Basic Render Driver, or loses WebGL entirely. Servers running bots look the same, so checkers treat it with suspicion.
- Hybrid-GPU laptops. A laptop with integrated and dedicated graphics can report different GPUs depending on power settings or which one the browser was assigned.
- Browsers that protect you on purpose. Safari reports a generic “Apple GPU” to every site. Firefox coarsens the renderer name to a broad family. Brave gives every user the same generic GPU name and adds small per-site variations to other WebGL outputs, which it calls farbling. Good checkers allowlist these. Lazy ones flag them anyway.
The difference between these and a spoof is consistency. Safari saying “Apple GPU” on an Apple device is a shared, honest answer. A Windows browser claiming an Apple GPU is a contradiction.
How to change or block your WebGL fingerprint
- Leave WebGL on. Disabling it makes you rarer, not safer, and breaks real sites.
- Remove WebGL spoofing extensions. Name-swappers and noise injectors create exactly the contradictions checkers look for. If the widget above flags patched functions or unstable pixels, an extension is the usual suspect.
- If you need a different identity, change every part of it. Running several accounts for ad verification, e-commerce or social media means every profile needs a GPU that fits its operating system, a vendor that fits its renderer, and pixels that fit its GPU. That is hard to fake in JavaScript, which is why anti-detect browsers do it inside the engine. Incogniton gives each profile a consistent WebGL identity at the browser level, with no patched functions for a checker to find.
Then run the full browser scan to see how your GPU fits with everything else your browser reports, from time zone to fonts.