Skip to content

Web Neural Network API 2025-03-20 > 2025-06-20 #85

Description

@anssiko

Other comments:

This API has received security review in 2022 and 2024.

The specification has also continued to receive Chrome security team review as part of the implementation effort, following the initial Chrome security team review focused on the specification text.

The group has addressed all but one security-tracker issues reported. The remaining open issue is proposed to be addressed by new conformance tests which explicitly perform out-of-bounds access. In part for this purpose, the API has added new errors to to detect if the context is no longer available to fulfill requests e.g. due to a crash or other malfunction.

Further suggestions from security reviewers are welcome in particular for appropriate conformance tests for hardening possible failure paths.

Activity

  1. added
    CRIn Candidate Recommendation.
    pendingThis issue needs to get a reviewer assigned to it
    on Mar 20, 2025
  2. anssiko commented on Aug 21, 2025

    @anssiko
    MemberAuthor

    This is a last call for security review comments. If someone is actively reviewing this specification, please let us know here so we can plan our next publication schedule accordingly. Thank you!

  3. simoneonofri commented on Sep 29, 2025

    @simoneonofri
    Contributor

    hi @anssiko, thank you for the reminder.

    I have read the Security Considerations. They are well-written in a narrative form, and I have no particular comments; I agree with what is noted.

    I don't know if you think this Threat Model (in progress) could be useful.

    https://github.com/w3c-cg/threat-modeling/blob/main/models/ai-in-browser.md

    Thank you,

    Simone

  4. anssiko commented on Sep 30, 2025

    @anssiko
    MemberAuthor

    @simoneonofri thank you for your review!

    I've penciled in discussion on security to the WebML WG/CG's TPAC agenda. Would you prefer Mon or Tue on the TPAC week? This is relevant to both the WebNN API (WG) and various LLM-backed built-in AI APIs (CG), thus we have flexibility in scheduling the security discussion.

  5. anssiko commented on Oct 3, 2025

    @anssiko
    MemberAuthor

    I added the threat model to the group's TPAC F2F agenda webmachinelearning/meetings#35 for further discussion.

    @simoneonofri, feel free to remove the pending label from this issue.

    I will close this review issue now as completed. Thank you again!

  6. removed
    pendingThis issue needs to get a reviewer assigned to it
    on Feb 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions