What it is
WebGL exposes the graphics stack: the unmasked vendor and renderer strings name the GPU and driver, dozens of parameters describe its limits (texture sizes, precision formats, extensions), and rendering a small scene produces pixels that depend on the exact driver.
How websites read it
const gl = canvas.getContext('webgl');
const ext = gl.getExtension('WEBGL_debug_renderer_info');
gl.getParameter(ext.UNMASKED_VENDOR_WEBGL); // "Apple"
gl.getParameter(ext.UNMASKED_RENDERER_WEBGL); // "ANGLE (Apple, ANGLE Metal Renderer: Apple M2, ...)"The strings come from the WEBGL_debug_renderer_info extension; the parameters from getParameter(); the image from drawing a shader into an offscreen canvas and hashing the result — the same recipe as the canvas fingerprint, one layer lower.
Why it identifies you
GPU model plus driver version plus OS is a narrow combination, and the rendered pixels are stable for as long as the driver is. Together they are one of the strongest hardware signals a page can collect.
How risk-control systems use it
The renderer string is checked against the OS and CPU: an Apple GPU needs a Mac and an ARM architecture hint, a GeForce does not belong on a phone, and SwiftShader or llvmpipe means software rendering — typical of virtual machines and headless browsers. getParameter is also checked for being native code, and the parameter set for matching the named GPU.
Common mistakes
A renderer string edited by hand with parameters left from the real card; an NVIDIA name on an Apple-silicon Mac; hooking getParameter; random per-call noise on the image so two renders never match.
Mango is accepting waitlist registrations. These capabilities describe its first release; client access opens with invitations.
How Mango Browser handles it
NoiseRenderer strings from a per-OS pool of real GPUs (Apple / Intel / NVIDIA / AMD); image noise is seeded per profile so the hash is unique yet stable.
Check yours
Jump to this signal in your scan results.