Log message:
www/firefox: Update to 153.0
Cnangelog:
153.0:
New
* High Dynamic Range (HDR) video playback is now available on Windows - this
feature needs HDR mode enabled for the display in Windows Settings -
Display. Laptop displays that only offer "HDR video streaming" are not
supported at this time. Some videos recorded on phones in certain
orientations are currently not shown as HDR.
* Containers let you keep separate parts of your online life (work, shopping,
personal, banking) logged into different accounts in the same browser
window, but keep your cookies and ad tracking isolated inside each
container.
* Share any open page with a QR code. Right-click a tab, select Share >
Generate QR Code. Great for posters, invitations, banners, and other
printed materials.
* It is now possible to merge multiple PDFs by dragging a PDF into the PDF
sidebar.
* It is now possible to add images as new pages within PDFs using the Firefox
PDF editor.
* Quickly pick and copy a color from any page by typing "pick \
color", "color
picker", or "eyedropper" in the address bar and selecting the \
"Pick a
color" quick action.
* Added support for Apple's system-wide full-screen keyboard command
(Globe-F).
* Firefox now verifies and displays Qualified Website Authentication
Certificates (QWACs) in accordance with eIDAS regulations.
* Added improved support for videos with overlays so users can more easily
access video actions from context menus.
* Firefox now highlights the location permission icon in red whenever a
website has access to your location. The permission icon is also now
visible on search results pages where it was previously hidden.
Screenshot of the red geolocation warning in the address bar when the
Geolocation API is being used
* Smart Window:
+ See and choose AI models directly from the Smart Window assistant.
+ New Tab now includes a familiar address bar for typing websites and
searching the web.
Firefox Labs
* Firefox Labs can now be opened quickly by typing "labs" or \
"experiment" in
the address bar and selecting the Open Firefox Labs quick action.
* Firefox now offers experimental support for the new JPEG XL image format,
which generally provides better compression than WebP, JPEG, PNG, and GIF
and is designed to supersede them. You can enable it from the Firefox Labs
panel in Settings.
Fixed
* Various security fixes.
Changed
* Extensions can no longer access local files by default. Users can grant or
revoke this access via the new "Access local files on your computer"
permission, separate from "Access your data for all websites".
* Local Network Access restrictions are now enabled by default for all users.
Firefox requires websites to request permission before connecting to
devices on your local network or to apps and services on your device.
* Outdated cookie settings have been removed from the Settings UI. Users
still in that mode should switch to default behavior "Isolate cross-site
cookies". More information
Security fixes:
Mozilla Foundation Security Advisory 2026-68
#CVE-2026-16349: Same-origin policy bypass in the DOM: Navigation component
#CVE-2026-16350: Incorrect boundary conditions in the Audio/Video: cubeb
component
#CVE-2026-16362: Use-after-free in the WebRTC: Audio/Video component
#CVE-2026-16351: Sandbox escape due to use-after-free in the DOM: Navigation
component
#CVE-2026-16352: Sandbox escape due to use-after-free in the Disability Access
APIs component
#CVE-2026-16363: JIT miscompilation in the JavaScript: WebAssembly component
#CVE-2026-16364: Incorrect boundary conditions in the Audio/Video: Playback
component
#CVE-2026-16365: Privilege escalation in the DOM: Workers component
#CVE-2026-16366: Privilege escalation in the DOM: Navigation component
#CVE-2026-16353: Invalid pointer in the DOM: Bindings (WebIDL) component
#CVE-2026-16354: Information disclosure in the Graphics: ImageLib component
#CVE-2026-16367: Sandbox escape due to invalid pointer in the Disability Access
APIs component
#CVE-2026-16368: Incorrect boundary conditions in the JavaScript: WebAssembly
component
#CVE-2026-16369: Integer overflow in the JavaScript: WebAssembly component
#CVE-2026-16355: JIT miscompilation in the JavaScript Engine: JIT component
#CVE-2026-16356: Sandbox escape due to use-after-free in the Disability Access
APIs component
#CVE-2026-16357: Incorrect boundary conditions in the Graphics component
#CVE-2026-16370: Mitigation bypass in the DOM: Networking component
#CVE-2026-16371: Privilege escalation in the DOM: Navigation component
#CVE-2026-16372: Privilege escalation in the DOM: Content Processes component
#CVE-2026-16373: Information disclosure in the Privacy component in Firefox for
Android
#CVE-2026-16374: Information disclosure in the Framework component in DevTools
#CVE-2026-16375: Site isolation issue in the Networking: HTTP component
#CVE-2026-16376: Denial-of-service in the Graphics: WebGPU component
#CVE-2026-16377: Mitigation bypass in the PDF Viewer component
#CVE-2026-16378: Other issue in the DOM: Copy & Paste and Drag & Drop \
component
#CVE-2026-16379: Privilege escalation in the DOM: Content Processes component
#CVE-2026-16358: Site isolation issue in the Graphics: WebRender component
#CVE-2026-16380: Mitigation bypass in the Networking component
#CVE-2026-16381: Same-origin policy bypass in the Networking: DNS component
#CVE-2026-16382: Mitigation bypass in the DOM: Service Workers component
#CVE-2026-16383: Mitigation bypass in the DOM: Networking component
#CVE-2026-16384: Information disclosure due to uninitialized memory in the
#CVE-2026-16385: Information disclosure due to uninitialized memory in the
Graphics: WebGPU component
#CVE-2026-16386: Information disclosure due to uninitialized memory in the
Graphics: WebGPU component
#CVE-2026-16387: Site isolation issue in the Networking component
#CVE-2026-16388: Sandbox escape in the DOM: Networking component
#CVE-2026-16389: Incorrect boundary conditions, integer overflow in the
#CVE-2026-16390: Mitigation bypass in the Enterprise Policies component
#CVE-2026-16391: Information disclosure in the Storage: IndexedDB component
#CVE-2026-16392: JIT miscompilation in the JavaScript Engine: JIT component
#CVE-2026-16393: Incorrect boundary conditions in the Graphics: WebGPU
#CVE-2026-16359: Incorrect boundary conditions in the Audio/Video: GMP
#CVE-2026-16394: Mitigation bypass in the DOM: Security component
#CVE-2026-16395: Integer overflow in the Audio/Video component
#CVE-2026-16396: Privilege escalation in WebExtensions
#CVE-2026-16397: Clickjacking issue in the WebExtensions component in Firefox
#CVE-2026-16398: Site isolation issue in the Graphics component
#CVE-2026-16399: Site isolation issue in the DOM: Navigation component
#CVE-2026-16400: Information disclosure in the DOM: Security component
#CVE-2026-16401: Privilege escalation in the Data Loss Prevention component
#CVE-2026-16402: Integer overflow in the Graphics: ImageLib component
#CVE-2026-16403: Spoofing issue in the Address Bar component
#CVE-2026-16404: Spoofing issue in Firefox for Android
#CVE-2026-16405: Information disclosure in the Networking: WebSockets component
#CVE-2026-16406: Mitigation bypass in the Networking component
#CVE-2026-16407: Mitigation bypass in the DOM: Service Workers component
#CVE-2026-16408: Integer overflow in the Audio/Video: Playback component
#CVE-2026-16409: Invalid pointer in the Security: PSM component
#CVE-2026-16410: JIT miscompilation in the JavaScript Engine: JIT component
#CVE-2026-16411: Memory safety bugs fixed in Firefox 153
#CVE-2026-16412: Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153
#CVE-2026-16360: Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR
140.13 and Firefox 153
|
Log message:
www/firefox: Update to 152.0.6
* WebGL does not work. webgl.out-of-process workaround was removed.
Disable WebGL by default.
Cnangelog:
152.0.6:
New
* Smart Window includes several enhancements:
Fixed
* Fixed an issue that prevented email tracking protection from being disabled
in the redesigned Firefox Settings. (Bug 2049331)
* Fixed a hang that could occur after using a file picker dialog on macOS 26.
(Bug 2053177)
* Fixed the homepage not loading for some enterprise configurations that set
it using a legacy autoconfig format. (Bug 2047962)
* Various security fixes.
Security fixes:
Mozilla Foundation Security Advisory 2026-67
#CVE-2026-15718: Invalid pointer in the JavaScript: WebAssembly component
#CVE-2026-15719: Site isolation in the DOM: Navigation component
152.0.5:
Fixed
* Fixed the Manage payment methods list in Settings appearing empty when a
saved payment card had no expiration date. (Bug 2048383)
152.0.4:
New
* Smart Window includes several enhancements:
+ You can now ask it to close your tabs, with a confirmation step when
needed and the option to undo afterward. (Bug 2040769)
+ Browsing history results now appear with images. (Bug 2038069)
+ When you give feedback on a response, you can now choose from common
reasons and preview exactly what will be shared before submitting. (Bug
2033002)
Fixed
* Fixed copy, paste, undo, redo, and similar keyboard shortcuts not working
inside macOS system dialogs such as the Save and Open panels. (Bug 2040851,
Bug 2040844)
* Fixed the Manage Cookies and Site Data dialog opening with an empty list
when opened from the Settings search results. (Bug 2041077)
* Fixed keyboard focus landing in the wrong place after following an in-page
link, so pressing Tab continues from the link's position as expected. (Bug
2049307)
* Various security fixes.
Security fixes:
Mozilla Foundation Security Advisory 2026-62
#CVE-2026-14241: Memory safety bugs fixed in Firefox 152.0.4
152.0.3:
Fixed
* Fixed an issue that could cause extreme memory usage and freezing on
startup for users with language packs installed. (Bug 2049845)
152.0.2:
Fixed
* Fixed some Settings section headings showing placeholder text instead of
the translated name in certain languages. (Bug 2047983)
* Fixed New Tab content not matching the browser's display language after it
was changed. (Bug 2046945)
* Fixed a regression that could break playback of some MP4 video files. (Bug
2047467)
* Fixed a performance regression that could slow down sites performing many
encryption and decryption operations at once, such as Proton Drive. (Bug
2046401)
152.0.1:
Fixed
* Fixed frequent crashes affecting users with Intel Raptor Lake processors. (
Bug 2039575)
* Fixed an issue on macOS where choosing a PDF option, such as "Save as \
PDF",
from the system print dialog would send the job to your printer instead of
saving a file. (Bug 2047850)
152.0:
New
* Firefox Settings features a brand-new look with streamlined organization,
clearer groupings, and improved navigation for easier customization.
* In Private Browsing windows, you can now temporarily disable tracker
blocking for a tab if it's causing a site to break. When you reload a page
where trackers were blocked, Firefox shows a message offering to reload
without the stricter protections. All other tracking protections stay
active.
* You can now mute your browser from the address bar: type "mute" \
(or "shush"
or "sssh") and use the address bar quick action to silence every tab
currently playing sound across all Firefox windows.
* Improved support for more advanced cursor movement commands, including
those relating to paragraph boundaries, on macOS.
* On Windows and Linux, you can now copy links via the tab context menu by
right-clicking a tab and selecting Share > Copy Link, making it easy to
copy a link without switching to the tab first. When multiple tabs are
selected, you can copy all selected links at once. Windows users still
retain access to Microsoft sharing options from the Share menu.
* A "Send tab" toolbar button is now available which can be added \
via More
Tools > Customize Toolbar.
* The following languages are now available for Translations:
+ Basque
+ Galician
* Firefox builds in Croatian, English (UK), Georgian, Persian, Slovenian,
Tajik, Tamil, Tibetan, Turkish, Welsh, and Xhosa now come with a built-in
dictionary for the Firefox spellchecker.
Firefox Labs
* Firefox now offers experimental support for the new JPEG XL image format,
which generally provides better compression than WebP, JPEG, PNG, and GIF
and is designed to supersede them. You can enable it from the Firefox Labs
panel in Settings.
Fixed
* Fixed an issue where the Paste option could be missing from context menus
when editing content on sites such as Squarespace, LinkedIn, and eBay.
* Improved dragging images from Firefox to the desktop or Finder on macOS ??
images now save reliably and land where you drop them.
* In multiple monitor situations, the About Firefox window now more reliably
opens on the display with the most recently used Firefox window.
* Fixed arrow-key text navigation and word selection commands that moved in
the wrong direction in right-to-left text on macOS and Linux.
* Various security fixes.
Security fixes:
Mozilla Foundation Security Advisory 2026-57
#CVE-2026-12289: Privilege escalation in the Graphics: WebRender component
#CVE-2026-12290: Memory safety bug fixed in Firefox 152
#CVE-2026-12291: Use-after-free in the Networking: HTTP component
#CVE-2026-12292: Incorrect boundary conditions in the Web Audio component
#CVE-2026-12293: Use-after-free in the Graphics: WebGPU component
#CVE-2026-12294: Sandbox escape in the DOM: Workers component
#CVE-2026-12295: Sandbox escape in the DOM: Navigation component
#CVE-2026-12296: Sandbox escape in the Security: Process Sandboxing component
#CVE-2026-12297: Sandbox escape due to incorrect boundary conditions in the
Networking component
#CVE-2026-12298: Memory safety bug fixed in Firefox 152
#CVE-2026-12299: JIT miscompilation in the DOM: Core & HTML component
#CVE-2026-12300: Memory safety bug fixed in Firefox 152
#CVE-2026-12301: Memory safety bug fixed in Firefox 152
#CVE-2026-12302: Mitigation bypass in the DOM: Security component
#CVE-2026-12303: Information disclosure due to incorrect boundary conditions in
the Graphics: WebGPU component
#CVE-2026-12304: Same-origin policy bypass in the Networking: Cookies component
#CVE-2026-12305: Memory safety bug fixed in Firefox 152
#CVE-2026-12306: Memory safety bug fixed in Firefox 152
#CVE-2026-12307: Memory safety bug fixed in Firefox 152
#CVE-2026-12308: Memory safety bug fixed in Firefox 152
#CVE-2026-12309: Memory safety bug fixed in Firefox 152
#CVE-2026-12310: Memory safety bug fixed in Firefox 152
#CVE-2026-12311: Information disclosure, sandbox escape in the Security:
Process Sandboxing component
#CVE-2026-12312: Memory safety bug fixed in Firefox 152
#CVE-2026-12313: Information disclosure, sandbox escape in the Security:
Process Sandboxing component
#CVE-2026-12314: Memory safety bug fixed in Firefox 152
#CVE-2026-12315: Mitigation bypass in the DOM: Security component
#CVE-2026-12316: Mitigation bypass in the DOM: Security component
#CVE-2026-12317: Memory safety bug fixed in Firefox 152
#CVE-2026-12318: Incorrect boundary conditions in the Libraries component in
NSS
#CVE-2026-12319: Denial-of-service in the Audio/Video: Playback component
#CVE-2026-12320: Information disclosure in the Password Manager component
#CVE-2026-12321: JIT miscompilation in the JavaScript: WebAssembly component
#CVE-2026-12322: Clickjacking issue in the Widget: Gtk component
#CVE-2026-12323: Spoofing issue in the DOM: Core & HTML component
#CVE-2026-12324: Incorrect boundary conditions in the Graphics: CanvasWebGL
component
#CVE-2026-12325: Denial-of-service in the Graphics: ImageLib component
#CVE-2026-12326: Memory safety bugs fixed in Firefox 152 and Thunderbird 152
|