Earlier quoted context omitted.
You are free to enable WebGl in the settings and install a Plugin that allows for blocking/allowing WebGl. The default should be privacy if you install a browser that focuses on privacy.
Would you expect a "privacy focused" browser to offer you networking disabled by default but the ability to enable completely unrestricted networking in the settings (you can install a plugin for CORS and the like if you want) or to natively provide the privacy controls you need to actually use the browser? If the latter, why is it different depending which attack surface you ask about? If the former, why not just ma…
Obviously not, because at that point it can no longer be used to browse the web. (That said, "do no network requests" should be the default idle state of the browser until appropriate user interaction. Allowing CORS is also a horrible default but that ship has long sailed.)
I also disable WebGL in my Firefox profile and this does not inconvenience me in any way. So I do not think WebGL support is as instrumental to browsing the web as you claim; it entirely depends on what sites you visit. (And let's be honest here, a very significant majority of websites does not need WebGL.)