Yes, in a way. If you allow unauthorized code on your web page, be it JS or WebGL shaders or something else, it can and will execute and use your users.
, , WebGL XSS. , , , ( ), script , . , XSS " ", , . GPU XSS.
- WebGL, XSS, , , , , , , GPU.
, XSS, , , ! , , , Javascript, SQL, WebGL, .