Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
First find the call that throws. If it is getImageData(), toBlob() or toDataURL() after a cross-origin image was drawn, the likely cause is a tainted canvas—not Firefox’s Selenium screenshot command. If you only need an image of what the browser displays, use Selenium’s WebDriver screenshot API. If your page must read the image’s pixels, both the request and the image server must allow CORS.
Identify which operation is failing
“Cross-origin images in a canvas,” “The canvas has been tainted by cross-origin data” and “SecurityError” often point to the same underlying restriction, but the method named in the stack trace matters. A page can display an image from another origin without granting JavaScript permission to inspect that image’s pixels. Drawing the image into a canvas without the necessary CORS approval makes the canvas tainted; pixel-read and image-export operations are then blocked. MDN explains the canvas restriction and CORS requirements.
| Failing call | What to investigate first |
|---|---|
getImageData(), toBlob() or toDataURL() in page JavaScript |
Check whether the canvas contains an image loaded from another origin and whether that image request and response have CORS approval. |
driver.save_screenshot(), get_screenshot_as_png() or a full-document screenshot call |
Do not assume canvas tainting. Read the complete WebDriver exception and check the Selenium, geckodriver and Firefox versions, along with a minimal reproduction. |
A screenshot API and a canvas export serve different purposes. WebDriver captures browser-rendered pixels; it does not make a page’s canvas readable to JavaScript. Conversely, making an image CORS-enabled is relevant when application code needs pixel access, not when Selenium simply needs to save a browser capture.
If your application needs to read the image pixels
The legitimate fix requires cooperation from the image server. The browser must make a CORS-enabled request for the image, and the server must return an Access-Control-Allow-Origin response header that permits the page’s origin. Setting an attribute in the page alone cannot grant access to a server that does not authorize it.
#1 Best Overall
- 【Windows Hello Compatible 4K Webcam】This usb camera has a mini design, but it's powerful in functionality. More than just a regular web camera, it integrates a dedicated infrared camera for facial-recognition. Log in to your Windows PC securely and instantly with facial recognition via Windows Hello.
- 【4K Ultra HD Resolution with 3D DNR Tech】Built-in 4K UHD 1/2.55" CMOS sensor, outputs up to 3840×2160 resolution crystal-clear image and 4K@30fps smooth video quality. With 3D Digital Noise Reduction (DNR) technology, intelligently reduces grain and visual noise in low-light conditions, delivering smooth, clean, and professional-quality footage in every video call, meeting, and live streaming.
- 【Smart Auto-Focus】Advanced auto-focus ensures you stay sharp and detailed. Ideal for live streaming, ensuring every detail is captured perfectly, even when you move or zoom in on a detail.
- 【Built-in Noise-Canceling Mic & Wide 83° Angle】Built-in microphone with noise-reduction, captures your voice clearly while minimizing background sound. Enjoy a wider, more natural frame with the 83° field of view.
- 【USB Plug-and-Play & Privacy Protection】Simply connect your PC via USB or USB-C for instant use—no drivers and App needed. With a built-in physical sliding privacy shutter blocks the lens when not in use for privacy protection.
Set up the image request before drawing
Set the image element’s crossOrigin property before assigning its src. Wait for the image’s load event before drawing it. The following browser-side example shows the required order; replace the image URL with one whose host is configured to permit your page’s origin:
const image = new Image();
image.crossOrigin = "anonymous";
image.addEventListener("load", () => {
const canvas = document.createElement("canvas");
canvas.width = image.naturalWidth;
canvas.height = image.naturalHeight;
const context = canvas.getContext("2d");
context.drawImage(image, 0, 0);
// These exports require the image host to have permitted CORS.
const pixels = context.getImageData(0, 0, canvas.width, canvas.height);
canvas.toBlob((blob) => {
// Use the resulting blob in your application.
});
});
image.addEventListener("error", () => {
console.error("The image failed to load; check its URL and CORS response.");
});
image.src = "https://images.example.com/photo.png";
The example’s placeholder host is not a working image service; use an actual image URL and configure that server to authorize the page’s origin. MDN’s CORS-enabled canvas guidance describes both the client request and the server response requirement.
When you cannot configure the image host
If the image host does not permit your origin, page JavaScript cannot override that decision. Do not disable Firefox’s security protections or weaken origin checks as a workaround. For an authorized use case, move the operation to a server-side workflow that has permission to retrieve the image, or avoid reading its pixels in page code. If the requirement is only to save what Firefox rendered, use a WebDriver screenshot instead.
Free tools Windows power users keep installed
One-click scans. No signup required.
If you only need a Selenium screenshot
Use the Firefox WebDriver screenshot methods rather than drawing page content into a canvas and exporting it. Selenium’s Firefox driver documents viewport screenshot methods and full-document methods such as get_full_page_screenshot_as_png() and get_full_page_screenshot_as_file(...). See the Selenium Firefox WebDriver API for the available methods in your installed binding.
Save the visible viewport
This Python example opens a page, saves the visible browser viewport as a PNG, and closes the driver even if capture fails:
Rank #2
- Compatible with Windows Hello Face Login: Say goodbye to complicated password. Set your computer sign-in option for windows hello then you can unlock your computer in seconds without entering a password. Note: Only works for windows 10 and above system with the Hello Face feature enabled
- 2K Quad HD: Equipped with 2K 5MP Lens, this 2K webcam provides definitely sharper and crisp image quality, making it perfect for online meetings and video calling. Auto light correction ensures this 2K camera works well even in dim light
- Noise-reducing Microphone: Built-in microphone catches your voice clearly while reducing background noise. This webcam with microphone delivers clear audio and your words will be heard clearly
- Wide Field of View: 84°wide-angle view is ideal for fitting more background into the frame during your personal video calls and online meetings, ensure nothing is out of the conversation. And this webcam with sliding privacy cover helps to protect you when you do not need camera during meetings
- Easy to Use: Includes adapter to switch between USB-C and USB-A for your computer. Everything is auto-on once this USB webcam is plugged in then the camera and mic are enabled. And it works well with popular video and conference platform including Microsoft Teams, Zoom, Google Meet
from selenium import webdriver
driver = webdriver.Firefox()
try:
driver.get("https://example.com")
saved = driver.save_screenshot("capture.png")
if not saved:
raise RuntimeError("WebDriver did not save the screenshot")
finally:
driver.quit()
Remove the extra leading space before driver = if copying this block into a Python file; the statements inside try and finally should each be indented one level. The page URL is an example: change it to the page you are authorized to capture. save_screenshot() writes a file; use get_screenshot_as_png() when your code needs the PNG bytes instead of a file.
Save the full document
If the page is longer than the viewport and you need a full-document image, use a full-page method exposed by your Selenium Firefox driver rather than assuming a viewport capture includes content below the fold:
Recommended Free Tools
from selenium import webdriver
driver = webdriver.Firefox()
try:
driver.get("https://example.com")
driver.get_full_page_screenshot_as_file("full-page.png")
finally:
driver.quit()
As above, align the Python indentation before running. The Firefox API also documents get_full_page_screenshot_as_png() for code that needs returned bytes. Choose viewport or full-document output based on the artifact you need; check the API documentation for the installed Selenium version if a method is unavailable.
Distinguish capture failures from canvas errors
If the exception comes from a WebDriver screenshot command, collect its full text and stack trace, identify the exact command, and reproduce the failure with the smallest page and script that still triggers it. Record the Selenium, geckodriver and Firefox versions. Those details help separate a driver or browser capture failure from a page-level canvas security exception; changing CORS headers will not by itself repair a failing WebDriver command.
Firefox’s screenshot readback preference is not a CORS fix
Firefox Source Docs describe remote.screenshot.use_readback as a WebRender debugging aid. When enabled, WebDriver and Marionette screenshots read the composited framebuffer rather than re-rendering through the software drawSnapshot path. The documented default is false; readback is limited to pixels currently composited in the foreground tab, so full-document, clipped and element captures degrade to viewport captures. The preference is not a workaround for page JavaScript calling getImageData(), toBlob() or toDataURL() on a tainted canvas. See the Firefox remote preferences documentation.
Rank #3
- Full HD Video: High-definition 1080p 30fps webcam with 1/2.9” CMOS image sensor. Delivers sharp, smooth video for Skype calls, Zoom meetings, and video recordings. There’s also a privacy cover for extra security and peace of mind when you’re not using the webcam.
- Dual Integrated Stereo Microphones: The two noise-reduction microphones ensure clear, natural sound with significantly reduced background noise.
- Auto Light Correction System: Balance brightness and color for sharp and smooth video. Auto exposure control maintains clarity & detail by ensuring video isn’t too dark or too bright. Auto white balance provides purer whites and rich, accurate color tones.
- Easy to Use: Clip the webcam onto a computer monitor or laptop, stand on a desk, or mount on a tripod (sold separately). Plug it into your device’s USB port and start using it right away (no drivers or software to install). 360° rotation allows convenient camera angle adjustment.
- Wide Compatibility: Compatible with Windows XP/7/8/10, Mac OS 10.6, Linux, Chrome OS, and Android 5.0 or above. Works with Skype, Zoom, FaceTime, Facebook Messenger, YouTube, and more.
Or skip the browser setup
If you need a hosted screenshot rather than a Selenium-controlled Firefox session, ScreenshotNeo is a website screenshot API and MCP server. One GET request can return an image or PDF; the example below requests a WebP screenshot. See the ScreenshotNeo API documentation for options and response details.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →curl -G "https://api.screenshotneo.com/v1/shot"
-d access_key=YOUR_API_KEY
--data-urlencode url=https://example.com
-o shot.webp
Equivalent Python request:
import requests
r = requests.get(
"https://api.screenshotneo.com/v1/shot",
params={"access_key": "YOUR_API_KEY", "url": "https://example.com"},
timeout=90,
)
open("shot.webp", "wb").write(r.content)
Equivalent Node.js request:
const q = new URLSearchParams({
access_key: 'YOUR_API_KEY',
url: 'https://example.com'
});
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
- Before capture, ScreenshotNeo accepts cookie or consent banners like a visitor and removes 60+ known consent platforms, newsletter popups and chat widgets. Each step can be turned off.
- Bot checks or CAPTCHAs, blank pages, timeouts, failed loads and cache hits cost nothing; responses identify page verdict and billing status in headers.
- Its MCP server provides
take_screenshot,get_page_infoandcapture_pdftools for Claude, Cursor and other MCP clients. - The free plan includes 1,000 screenshots per month with no card. Paid plans start at $5 for 3,000 screenshots; every feature is available on every plan.
Sign up for 1,000 free screenshots a month, with no card required.
Troubleshooting by symptom
| Symptom | Likely cause | Next step |
|---|---|---|
“The canvas has been tainted by cross-origin data” or a SecurityError at a canvas read/export call |
A foreign-origin image was drawn without CORS approval. | Confirm the image request uses crossOrigin before src, and that the image server returns an Access-Control-Allow-Origin header permitting your page. |
| The image displays, but canvas pixel access fails | Displaying the image does not establish permission for JavaScript to inspect its pixels. | Have the image server authorize the page’s origin, or use an authorized server-side workflow instead. |
The stack trace points to save_screenshot() or another WebDriver screenshot method |
The failure is in the browser/driver capture path, not necessarily canvas security. | Inspect the full exception and reproduce minimally; note Selenium, geckodriver and Firefox versions. |
| A full-page method is missing or does not produce the expected scope | The installed Selenium binding or Firefox capture path may not expose the expected method or behavior. | Check the Firefox API docs for the installed binding, and decide whether viewport or full-document output is required. |
| Readback captures only what is visible | remote.screenshot.use_readback is constrained to the currently composited foreground-tab pixels. |
Do not use it when you need full-document, clipped or element capture; it is a debugging preference, not a general remedy. |
When asking for help, include the exact failing method, complete exception and stack trace, a minimal reproduction, and the Selenium, geckodriver and Firefox versions. The phrase “SecurityError” alone does not distinguish a page canvas violation from a WebDriver command failure. The Firefox issue tracked in Mozilla Bugzilla 1294306 is useful context for screenshot-path questions, but the actual failure still needs to be diagnosed from its operation and environment.
Frequently Asked Questions
Does a cross-origin SecurityError mean Firefox blocked the screenshot file?
Not necessarily. If the exception is raised by page canvas code, the blocked action is pixel readback or export from that canvas. A separate WebDriver screenshot command may still capture the rendered page.
Should I change Firefox preferences to make canvas pixels readable?
No. The documented screenshot readback preference concerns WebDriver/Marionette capture and compositing, not permission for page JavaScript to read cross-origin image pixels.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsWhat information should I include in a bug report?
Name the exact call that fails and provide the complete exception, stack trace, a minimal reproduction, and the Selenium, geckodriver and Firefox versions.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

