./www/firefox, Web browser with support for extensions (version 153)

[ CVSweb ] [ Homepage ] [ RSS ] [ Required by ]


Branch: CURRENT, Version: 153.0, Package name: firefox-153.0, Maintainer: ryoon

Mozilla Firefox is a free, open-source and cross-platform web browser
for Windows, Linux, MacOS X and many other operating systems.

It is fast and easy to use, and offers many advantages over other web
browsers, such as tabbed browsing and the ability to block pop-up
windows.

Firefox also offers excellent bookmark and history management, and it
can be extended by developers using industry standards such as XML,
CSS, JavaScript, C++, etc. Many extensions are available.

Note: Due to upstream's trademark policies, this package identifies as
"Nightly" rather than "Firefox" by default.


Required to run:
[sysutils/desktop-file-utils] [sysutils/dbus-glib] [textproc/icu] [graphics/MesaLib] [net/libIDL] [devel/nspr] [devel/libevent] [devel/libffi] [devel/nss] [x11/gtk2] [x11/pixman] [x11/gtk3] [graphics/libwebp] [multimedia/ffmpeg4]

Required to build:
[pkgtools/x11-links] [databases/py-sqlite3] [x11/xcb-proto] [lang/clang] [x11/fixesproto4] [pkgtools/cwrappers] [x11/xorgproto] [lang/rust-bin]

Package options: sunaudio, webrtc

Master sites: (Expand)

Filesize: 785407.137 KB

Version history: (Expand)


CVS history: (Expand)


   2026-07-21 17:25:02 by Ryo ONODERA | Files touched by this commit (8)
Log message:
www/firefox: Update to 153.0

Cnangelog:
153.0:
New

  * High Dynamic Range (HDR) video playback is now available on Windows - this
    feature needs HDR mode enabled for the display in Windows Settings -
    Display. Laptop displays that only offer "HDR video streaming" are not
    supported at this time. Some videos recorded on phones in certain
    orientations are currently not shown as HDR.

  * Containers let you keep separate parts of your online life (work, shopping,
    personal, banking) logged into different accounts in the same browser
    window, but keep your cookies and ad tracking isolated inside each
    container.

  * Share any open page with a QR code. Right-click a tab, select Share >
    Generate QR Code. Great for posters, invitations, banners, and other
    printed materials.

  * It is now possible to merge multiple PDFs by dragging a PDF into the PDF
    sidebar.

  * It is now possible to add images as new pages within PDFs using the Firefox
    PDF editor.

  * Quickly pick and copy a color from any page by typing "pick \ 
color", "color
    picker", or "eyedropper" in the address bar and selecting the \ 
"Pick a
    color" quick action.

  * Added support for Apple's system-wide full-screen keyboard command
    (Globe-F).

  * Firefox now verifies and displays Qualified Website Authentication
    Certificates (QWACs) in accordance with eIDAS regulations.

  * Added improved support for videos with overlays so users can more easily
    access video actions from context menus.

  * Firefox now highlights the location permission icon in red whenever a
    website has access to your location. The permission icon is also now
    visible on search results pages where it was previously hidden.

    Screenshot of the red geolocation warning in the address bar when the
    Geolocation API is being used

  * Smart Window:

      + See and choose AI models directly from the Smart Window assistant.
      + New Tab now includes a familiar address bar for typing websites and
        searching the web.

Firefox Labs

  * Firefox Labs can now be opened quickly by typing "labs" or \ 
"experiment" in
    the address bar and selecting the Open Firefox Labs quick action.

  * Firefox now offers experimental support for the new JPEG XL image format,
    which generally provides better compression than WebP, JPEG, PNG, and GIF
    and is designed to supersede them. You can enable it from the Firefox Labs
    panel in Settings.

Fixed

  * Various security fixes.

Changed

  * Extensions can no longer access local files by default. Users can grant or
    revoke this access via the new "Access local files on your computer"
    permission, separate from "Access your data for all websites".

  * Local Network Access restrictions are now enabled by default for all users.
    Firefox requires websites to request permission before connecting to
    devices on your local network or to apps and services on your device.

  * Outdated cookie settings have been removed from the Settings UI. Users
    still in that mode should switch to default behavior "Isolate cross-site
    cookies". More information

Security fixes:
Mozilla Foundation Security Advisory 2026-68
#CVE-2026-16349: Same-origin policy bypass in the DOM: Navigation component
#CVE-2026-16350: Incorrect boundary conditions in the Audio/Video: cubeb
 component
#CVE-2026-16362: Use-after-free in the WebRTC: Audio/Video component
#CVE-2026-16351: Sandbox escape due to use-after-free in the DOM: Navigation
 component
#CVE-2026-16352: Sandbox escape due to use-after-free in the Disability Access
 APIs component
#CVE-2026-16363: JIT miscompilation in the JavaScript: WebAssembly component
#CVE-2026-16364: Incorrect boundary conditions in the Audio/Video: Playback
 component
#CVE-2026-16365: Privilege escalation in the DOM: Workers component
#CVE-2026-16366: Privilege escalation in the DOM: Navigation component
#CVE-2026-16353: Invalid pointer in the DOM: Bindings (WebIDL) component
#CVE-2026-16354: Information disclosure in the Graphics: ImageLib component
#CVE-2026-16367: Sandbox escape due to invalid pointer in the Disability Access
 APIs component
#CVE-2026-16368: Incorrect boundary conditions in the JavaScript: WebAssembly
 component
#CVE-2026-16369: Integer overflow in the JavaScript: WebAssembly component
#CVE-2026-16355: JIT miscompilation in the JavaScript Engine: JIT component
#CVE-2026-16356: Sandbox escape due to use-after-free in the Disability Access
 APIs component
#CVE-2026-16357: Incorrect boundary conditions in the Graphics component
#CVE-2026-16370: Mitigation bypass in the DOM: Networking component
#CVE-2026-16371: Privilege escalation in the DOM: Navigation component
#CVE-2026-16372: Privilege escalation in the DOM: Content Processes component
#CVE-2026-16373: Information disclosure in the Privacy component in Firefox for
 Android
#CVE-2026-16374: Information disclosure in the Framework component in DevTools
#CVE-2026-16375: Site isolation issue in the Networking: HTTP component
#CVE-2026-16376: Denial-of-service in the Graphics: WebGPU component
#CVE-2026-16377: Mitigation bypass in the PDF Viewer component
#CVE-2026-16378: Other issue in the DOM: Copy & Paste and Drag & Drop \ 
component
#CVE-2026-16379: Privilege escalation in the DOM: Content Processes component
#CVE-2026-16358: Site isolation issue in the Graphics: WebRender component
#CVE-2026-16380: Mitigation bypass in the Networking component
#CVE-2026-16381: Same-origin policy bypass in the Networking: DNS component
#CVE-2026-16382: Mitigation bypass in the DOM: Service Workers component
#CVE-2026-16383: Mitigation bypass in the DOM: Networking component
#CVE-2026-16384: Information disclosure due to uninitialized memory in the
#CVE-2026-16385: Information disclosure due to uninitialized memory in the
 Graphics: WebGPU component
#CVE-2026-16386: Information disclosure due to uninitialized memory in the
 Graphics: WebGPU component
#CVE-2026-16387: Site isolation issue in the Networking component
#CVE-2026-16388: Sandbox escape in the DOM: Networking component
#CVE-2026-16389: Incorrect boundary conditions, integer overflow in the
#CVE-2026-16390: Mitigation bypass in the Enterprise Policies component
#CVE-2026-16391: Information disclosure in the Storage: IndexedDB component
#CVE-2026-16392: JIT miscompilation in the JavaScript Engine: JIT component
#CVE-2026-16393: Incorrect boundary conditions in the Graphics: WebGPU
#CVE-2026-16359: Incorrect boundary conditions in the Audio/Video: GMP
#CVE-2026-16394: Mitigation bypass in the DOM: Security component
#CVE-2026-16395: Integer overflow in the Audio/Video component
#CVE-2026-16396: Privilege escalation in WebExtensions
#CVE-2026-16397: Clickjacking issue in the WebExtensions component in Firefox
#CVE-2026-16398: Site isolation issue in the Graphics component
#CVE-2026-16399: Site isolation issue in the DOM: Navigation component
#CVE-2026-16400: Information disclosure in the DOM: Security component
#CVE-2026-16401: Privilege escalation in the Data Loss Prevention component
#CVE-2026-16402: Integer overflow in the Graphics: ImageLib component
#CVE-2026-16403: Spoofing issue in the Address Bar component
#CVE-2026-16404: Spoofing issue in Firefox for Android
#CVE-2026-16405: Information disclosure in the Networking: WebSockets component
#CVE-2026-16406: Mitigation bypass in the Networking component
#CVE-2026-16407: Mitigation bypass in the DOM: Service Workers component
#CVE-2026-16408: Integer overflow in the Audio/Video: Playback component
#CVE-2026-16409: Invalid pointer in the Security: PSM component
#CVE-2026-16410: JIT miscompilation in the JavaScript Engine: JIT component
#CVE-2026-16411: Memory safety bugs fixed in Firefox 153
#CVE-2026-16412: Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153
#CVE-2026-16360: Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR
 140.13 and Firefox 153
   2026-07-17 20:21:44 by Izumi Tsutsui | Files touched by this commit (1)
Log message:
firefox: 152.0.* requires nss>=3.124
   2026-07-17 00:28:23 by Ryo ONODERA | Files touched by this commit (1)
Log message:
www/firefox: Update checksum of patched file

* I had confused with upcoming 153 package.
   2026-07-16 17:18:46 by Ryo ONODERA | Files touched by this commit (2)
Log message:
www/firefox: Try to fix builds under both of NetBSD/{i386,amd64}
   2026-07-16 15:11:49 by Ryo ONODERA | Files touched by this commit (9)
Log message:
www/firefox: Update to 152.0.6

* WebGL does not work. webgl.out-of-process workaround was removed.
  Disable WebGL by default.

Cnangelog:
152.0.6:
New
  * Smart Window includes several enhancements:

Fixed

  * Fixed an issue that prevented email tracking protection from being disabled
    in the redesigned Firefox Settings. (Bug 2049331)

  * Fixed a hang that could occur after using a file picker dialog on macOS 26.
    (Bug 2053177)

  * Fixed the homepage not loading for some enterprise configurations that set
    it using a legacy autoconfig format. (Bug 2047962)

  * Various security fixes.

Security fixes:
Mozilla Foundation Security Advisory 2026-67
#CVE-2026-15718: Invalid pointer in the JavaScript: WebAssembly component
#CVE-2026-15719: Site isolation in the DOM: Navigation component

152.0.5:
Fixed

  * Fixed the Manage payment methods list in Settings appearing empty when a
    saved payment card had no expiration date. (Bug 2048383)

152.0.4:
New

  * Smart Window includes several enhancements:

      + You can now ask it to close your tabs, with a confirmation step when
        needed and the option to undo afterward. (Bug 2040769)
      + Browsing history results now appear with images. (Bug 2038069)
      + When you give feedback on a response, you can now choose from common
        reasons and preview exactly what will be shared before submitting. (Bug
        2033002)

Fixed

  * Fixed copy, paste, undo, redo, and similar keyboard shortcuts not working
    inside macOS system dialogs such as the Save and Open panels. (Bug 2040851,
    Bug 2040844)

  * Fixed the Manage Cookies and Site Data dialog opening with an empty list
    when opened from the Settings search results. (Bug 2041077)

  * Fixed keyboard focus landing in the wrong place after following an in-page
    link, so pressing Tab continues from the link's position as expected. (Bug
    2049307)

  * Various security fixes.

Security fixes:
Mozilla Foundation Security Advisory 2026-62
#CVE-2026-14241: Memory safety bugs fixed in Firefox 152.0.4

152.0.3:
Fixed

  * Fixed an issue that could cause extreme memory usage and freezing on
    startup for users with language packs installed. (Bug 2049845)

152.0.2:
Fixed

  * Fixed some Settings section headings showing placeholder text instead of
    the translated name in certain languages. (Bug 2047983)

  * Fixed New Tab content not matching the browser's display language after it
    was changed. (Bug 2046945)

  * Fixed a regression that could break playback of some MP4 video files. (Bug
    2047467)

  * Fixed a performance regression that could slow down sites performing many
    encryption and decryption operations at once, such as Proton Drive. (Bug
    2046401)

152.0.1:
Fixed

  * Fixed frequent crashes affecting users with Intel Raptor Lake processors. (
    Bug 2039575)

  * Fixed an issue on macOS where choosing a PDF option, such as "Save as \ 
PDF",
    from the system print dialog would send the job to your printer instead of
    saving a file. (Bug 2047850)

152.0:
New

  * Firefox Settings features a brand-new look with streamlined organization,
    clearer groupings, and improved navigation for easier customization.

  * In Private Browsing windows, you can now temporarily disable tracker
    blocking for a tab if it's causing a site to break. When you reload a page
    where trackers were blocked, Firefox shows a message offering to reload
    without the stricter protections. All other tracking protections stay
    active.

  * You can now mute your browser from the address bar: type "mute" \ 
(or "shush"
    or "sssh") and use the address bar quick action to silence every tab
    currently playing sound across all Firefox windows.

  * Improved support for more advanced cursor movement commands, including
    those relating to paragraph boundaries, on macOS.

  * On Windows and Linux, you can now copy links via the tab context menu by
    right-clicking a tab and selecting Share > Copy Link, making it easy to
    copy a link without switching to the tab first. When multiple tabs are
    selected, you can copy all selected links at once. Windows users still
    retain access to Microsoft sharing options from the Share menu.

  * A "Send tab" toolbar button is now available which can be added \ 
via More
    Tools > Customize Toolbar.

  * The following languages are now available for Translations:

      + Basque
      + Galician
  * Firefox builds in Croatian, English (UK), Georgian, Persian, Slovenian,
    Tajik, Tamil, Tibetan, Turkish, Welsh, and Xhosa now come with a built-in
    dictionary for the Firefox spellchecker.

Firefox Labs

  * Firefox now offers experimental support for the new JPEG XL image format,
    which generally provides better compression than WebP, JPEG, PNG, and GIF
    and is designed to supersede them. You can enable it from the Firefox Labs
    panel in Settings.

Fixed

  * Fixed an issue where the Paste option could be missing from context menus
    when editing content on sites such as Squarespace, LinkedIn, and eBay.

  * Improved dragging images from Firefox to the desktop or Finder on macOS ??
    images now save reliably and land where you drop them.

  * In multiple monitor situations, the About Firefox window now more reliably
    opens on the display with the most recently used Firefox window.

  * Fixed arrow-key text navigation and word selection commands that moved in
    the wrong direction in right-to-left text on macOS and Linux.

  * Various security fixes.

Security fixes:
Mozilla Foundation Security Advisory 2026-57
#CVE-2026-12289: Privilege escalation in the Graphics: WebRender component
#CVE-2026-12290: Memory safety bug fixed in Firefox 152
#CVE-2026-12291: Use-after-free in the Networking: HTTP component
#CVE-2026-12292: Incorrect boundary conditions in the Web Audio component
#CVE-2026-12293: Use-after-free in the Graphics: WebGPU component
#CVE-2026-12294: Sandbox escape in the DOM: Workers component
#CVE-2026-12295: Sandbox escape in the DOM: Navigation component
#CVE-2026-12296: Sandbox escape in the Security: Process Sandboxing component
#CVE-2026-12297: Sandbox escape due to incorrect boundary conditions in the
 Networking component
#CVE-2026-12298: Memory safety bug fixed in Firefox 152
#CVE-2026-12299: JIT miscompilation in the DOM: Core & HTML component
#CVE-2026-12300: Memory safety bug fixed in Firefox 152
#CVE-2026-12301: Memory safety bug fixed in Firefox 152
#CVE-2026-12302: Mitigation bypass in the DOM: Security component
#CVE-2026-12303: Information disclosure due to incorrect boundary conditions in
 the Graphics: WebGPU component
#CVE-2026-12304: Same-origin policy bypass in the Networking: Cookies component
#CVE-2026-12305: Memory safety bug fixed in Firefox 152
#CVE-2026-12306: Memory safety bug fixed in Firefox 152
#CVE-2026-12307: Memory safety bug fixed in Firefox 152
#CVE-2026-12308: Memory safety bug fixed in Firefox 152
#CVE-2026-12309: Memory safety bug fixed in Firefox 152
#CVE-2026-12310: Memory safety bug fixed in Firefox 152
#CVE-2026-12311: Information disclosure, sandbox escape in the Security:
 Process Sandboxing component
#CVE-2026-12312: Memory safety bug fixed in Firefox 152
#CVE-2026-12313: Information disclosure, sandbox escape in the Security:
 Process Sandboxing component
#CVE-2026-12314: Memory safety bug fixed in Firefox 152
#CVE-2026-12315: Mitigation bypass in the DOM: Security component
#CVE-2026-12316: Mitigation bypass in the DOM: Security component
#CVE-2026-12317: Memory safety bug fixed in Firefox 152
#CVE-2026-12318: Incorrect boundary conditions in the Libraries component in
 NSS
#CVE-2026-12319: Denial-of-service in the Audio/Video: Playback component
#CVE-2026-12320: Information disclosure in the Password Manager component
#CVE-2026-12321: JIT miscompilation in the JavaScript: WebAssembly component
#CVE-2026-12322: Clickjacking issue in the Widget: Gtk component
#CVE-2026-12323: Spoofing issue in the DOM: Core & HTML component
#CVE-2026-12324: Incorrect boundary conditions in the Graphics: CanvasWebGL
 component
#CVE-2026-12325: Denial-of-service in the Graphics: ImageLib component
#CVE-2026-12326: Memory safety bugs fixed in Firefox 152 and Thunderbird 152
   2026-07-13 06:36:42 by Thomas Klausner | Files touched by this commit (846)
Log message:
*: recursive bump for libmpg123 dependency in lame
   2026-07-09 22:07:10 by John Klos | Files touched by this commit (2)
Log message:
PR pkg/59775

Installed suggested patch to fix compiling on NetBSD/aarch64.
https://gnats.netbsd.org/59775
   2026-06-12 09:28:27 by Thomas Klausner | Files touched by this commit (1)
Log message:
firefox: fix whitespace pkglint