Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

First identify which call raises SecurityError. If it is canvas.getImageData(), canvas.toBlob(), or canvas.toDataURL() after a cross-origin image was drawn, the canvas is probably tainted: the image can be displayed, but page JavaScript cannot read its pixels without the image server’s CORS permission. If you only need an image of what Firefox displays, use Selenium’s WebDriver screenshot API instead of exporting a page canvas.

Find the operation that actually fails

“Cross-origin SecurityError” does not identify one universal Firefox screenshot failure. It can describe a page-level canvas export restriction, or it can be used loosely for an exception from a WebDriver command. Those cases need different remedies. Read the exception and stack trace, then note the exact failing method before changing browser settings.

  • Canvas read/export call fails: If the stack points to getImageData(), toBlob(), or toDataURL(), check whether a cross-origin image or other foreign-origin data was drawn into that canvas. MDN explains the browser’s [origin-clean and CORS restrictions](https://developer.mozilla.org/en-US/docs/Web/HTML/How_to/CORS_enabled_image).
  • WebDriver screenshot command fails: If the exception comes from save_screenshot(), get_screenshot_as_png(), or a full-document screenshot method, do not assume canvas tainting. Capture the full exception and inspect the Selenium, geckodriver, and Firefox versions, plus a minimal reproduction. Selenium documents its [Firefox WebDriver screenshot methods](https://www.selenium.dev/selenium/docs/api/py/selenium_webdriver_firefox/selenium.webdriver.firefox.webdriver.html).

The words “The canvas has been tainted by cross-origin data” point toward the first case, but error wording varies by browser and operation. The method named in the stack trace is more useful than the wording alone.

Choose the fix based on what you need from the screenshot

You need readable image pixels for application code

A page can often display a remote image without being allowed to inspect its pixels. Displaying an image and reading its pixel data are separate permissions. Drawing a cross-origin image without CORS approval taints the canvas; browser restrictions then prevent pixel reads or canvas export. See MDN’s guide to [using cross-origin images in a canvas](https://developer.mozilla.org/en-US/docs/Web/HTML/How_to/CORS_enabled_image).

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Freestyle 5 Books of Freestyle Self Testing Log Book Total 5 Books
  • The FreeStyle log book includes sections for: Lunch, Dinner, Bedtime, Night
  • Comments for each day of the week
  • Log Book Dimensions L=4.25" x W=3.12" x H=0.12"
  • Contains 5 book

For an authorized CORS request, set the image’s crossOrigin property before setting src, wait for the image to load, and then draw it. The image server must return an Access-Control-Allow-Origin header that permits your page’s origin. For example, if you control the server and it authorizes https://app.example, its response must allow that origin; a wildcard is appropriate only when the server’s policy permits it.

const image = new Image();
image.crossOrigin = "anonymous"; // Set before src.
image.onload = () => {
  const canvas = document.createElement("canvas");
  canvas.width = image.naturalWidth;
  canvas.height = image.naturalHeight;

  const context = canvas.getContext("2d");
  context.drawImage(image, 0, 0);

  // This succeeds only if the image server allowed the CORS request.
  canvas.toBlob((blob) => {
    if (!blob) throw new Error("Canvas export returned no image.");
    // Use the authorized image data here.
  }, "image/png");
};
image.onerror = () => console.error("Image load or CORS authorization failed.");
image.src = "https://images.example/image.png";

Replace the example origin and image URL with your own. The code does not grant itself access: if the remote server does not authorize the request, the canvas remains unreadable. Client-side JavaScript cannot override that server decision. If you do not control the host, use an authorized server-side workflow or avoid reading the foreign pixels in page JavaScript. Do not disable Firefox’s security protections to work around the restriction.

You only need a screenshot of the rendered page

Do not route a browser screenshot through page canvas code. Selenium’s Firefox WebDriver can save viewport screenshot bytes directly or capture the full document. The viewport methods capture the current browser view; the full-document methods are for content extending beyond it. These APIs avoid relying on a page-level canvas export for the screenshot.

A minimal Python example using the viewport screenshot is:

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Sale
Web Security Testing Cookbook
  • Used Book in Good Condition
from selenium import webdriver

url = "https://example.com"
driver = webdriver.Firefox()
try:
    driver.get(url)
    driver.save_screenshot("capture.png")
finally:
    driver.quit()

To work with the PNG bytes instead of saving directly to a file:

png_bytes = driver.get_screenshot_as_png()
with open("capture.png", "wb") as image_file:
    image_file.write(png_bytes)

For a full-document Firefox capture, use the Firefox-specific API:

driver.get_full_page_screenshot_as_file("full-page.png")

Or retrieve its bytes with get_full_page_screenshot_as_png() and write them to a file as in the viewport example. Consult Selenium’s [Firefox WebDriver API](https://www.selenium.dev/selenium/docs/api/py/selenium_webdriver_firefox/selenium.webdriver.firefox.webdriver.html) for the documented methods. Choose viewport capture when you need only what is visible in the current view; choose full-page capture when the output should include the whole document.

Or skip the browser setup

If your goal is a website image rather than Selenium-specific browser automation, ScreenshotNeo provides a screenshot API. One GET request returns an image or PDF; here is the cURL form, saving the result as WebP:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://example.com -o shot.webp

See the ScreenshotNeo API documentation for request options. ScreenshotNeo removes cookie/consent banners, newsletter popups, and chat widgets before capture; each step can be turned off. Bot checks/CAPTCHAs, blank pages, timeouts, failed loads, and cache hits cost nothing, and responses include X-Page-Verdict and X-Billed headers. Its MCP server exposes take_screenshot, get_page_info, and capture_pdf for AI agents and MCP clients. The Free plan includes 1,000 shots per month with no card; paid plans start at $5 for 3,000 shots.

Sign up for ScreenshotNeo’s free plan to get 1,000 screenshots a month with no card.

Firefox’s screenshot readback preference is not a CORS fix

Firefox Source Docs describe remote.screenshot.use_readback as a WebRender debugging aid. When enabled, WebDriver and Marionette screenshots read the composited framebuffer instead of re-rendering through the software drawSnapshot path. The documented default is false, and readback is limited to pixels in the currently composited foreground tab. As a result, full-document, clipped, and element captures degrade to the viewport. This preference is not a way to authorize canvas pixel access or a general remedy for a tainted canvas. See the [Firefox remote preferences documentation](https://firefox-source-docs.mozilla.org/remote/Prefs.html).

Troubleshoot by symptom

Symptom Likely cause What to do
getImageData(), toBlob(), or toDataURL() throws after drawing an image The canvas was tainted by cross-origin data that the image server did not authorize for CORS. Confirm the image request is CORS-enabled, set crossOrigin before src, and verify that the response permits the page’s origin. If you only need a screenshot, use Selenium’s screenshot API.
Adding crossOrigin = "anonymous" did not fix canvas export The client request alone is insufficient; the image server may not return an allowing Access-Control-Allow-Origin header, or the property may have been set after src. Set the property before src and inspect the image response headers. The host must authorize the request.
driver.save_screenshot() or get_screenshot_as_png() raises an exception This is a WebDriver screenshot failure, not automatically a canvas origin-clean failure. Keep the full exception and reproduce with the smallest page and script possible; record Selenium, geckodriver, and Firefox versions. Check whether viewport capture works separately from full-document capture.
Full-page, clipped, or element capture becomes viewport-only after readback is enabled remote.screenshot.use_readback reads only currently composited foreground-tab pixels. Do not use this debugging preference when the required output is full-document, clipped, or element capture. Return to the normal screenshot path and use the appropriate WebDriver API.
A screenshot is saved but does not include the expected page content The capture may be viewport-only, or navigation may not have reached the intended page state when capture ran. Check the capture scope and the page’s loaded state. Use full-document capture for content beyond the viewport; if the WebDriver command itself fails, investigate the exception rather than changing CORS headers.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Reliability and cost considerations

For Selenium automation, keep screenshot capture in WebDriver and pixel analysis in a separate, explicitly CORS-authorized path. A CORS fix depends on an image server you control or that has chosen to authorize your page; if authorization is unavailable, no browser-side setting can legitimately supply it. For a website capture service, ScreenshotNeo bills only clean shots; its response headers identify the page verdict and billing status. Review the response rather than assuming every request produced a billable screenshot.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use the capture scope that matches the work. A viewport screenshot is generally the direct choice for visible-state checks; a full-document image can be larger and may expose issues associated with content loaded as the page is traversed. When debugging an inconsistent result, first separate page readiness, capture scope, and the specific failing command so a CORS change is not applied to a WebDriver problem.

Rank #4
Sale
Clever Fox Firearms Acquisition & Disposition Record Book, Gray
  • PREMIUM-QUALITY RECORD BOOK FOR DEALERS & COLLECTORS: Clever Fox Firearms Record Book is designed to help professional firearm dealers keep detailed and legally compliant acquisition and disposition information.
  • 129 PAGES WITH 1,342 NUMBERED ENTRIES TOTAL: There are 129 pages in this firearm log book with 1,342 numbered entries total. Each pre-printed entry allows you to record the firearm’s description, as well as receipt and disposition info.
  • LARGE FORMAT & PLENTY OF SPACE FOR EVERY DETAIL: This firearm record book comes in large format and measures 10 by 7 inches, so you have lots of space to make detailed records and add all the information you need.
  • STORAGE POCKET, DURABLE HARDCOVER & THICK NO-BLEED PAPER: This gun record book features a pocket for loose papers, a pen loop, an elastic band, and a bookmark. The hardcover is made of durable vegan leather. The pages are thick 120gsm paper.
  • 60-DAY MONEY-BACK GUARANTEE: We will exchange or refund your book of firearms if you aren’t satisfied with your personal firearms record book for any reason. Reach out to us via message to refund your personal gun log book.

What to include when asking for help

Report the exact failing method and include the complete exception and stack trace. For a canvas error, include whether the canvas drew a cross-origin image, the order in which crossOrigin and src were set, and the relevant CORS response header. For a WebDriver screenshot error, include the Selenium, geckodriver, and Firefox versions, whether the command was viewport or full-document, and a minimal script and page that reproduce it. Do not omit the operation name: it is what distinguishes a browser security restriction from an automation failure.

Frequently Asked Questions

Does Firefox block every image hosted on another domain?

No. A page may display an image while still being prevented from reading its pixels through canvas; display and pixel-read permissions differ.

Does Selenium’s screenshot API make a tainted canvas readable?

No. It captures browser-rendered pixels through WebDriver; it does not grant page JavaScript permission to read a foreign image’s pixels.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Can I fix a third-party image’s CORS policy from my page’s JavaScript?

No. The image server must authorize the requesting page in its response. Without that permission, use an authorized alternative rather than weakening browser security.

Quick Recap

Bestseller No. 1
Freestyle 5 Books of Freestyle Self Testing Log Book Total 5 Books
Freestyle 5 Books of Freestyle Self Testing Log Book Total 5 Books
The FreeStyle log book includes sections for: Lunch, Dinner, Bedtime, Night; Comments for each day of the week
$17.99
SaleBestseller No. 2
Web Security Testing Cookbook
Web Security Testing Cookbook
Used Book in Good Condition
$20.93
Bestseller No. 3

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.