Release of Firefox 93

The release of the Firefox 93 web browser has taken place. In addition, updates for the long-term support branches — 78.15.0 and 91.2.0 — have been formed. The Firefox 94 branch has entered beta testing, with the release scheduled for November 2.

Key innovations:

  • Support for the AVIF image format (AV1 Image Format) has been enabled by default, which utilizes intra-frame compression technologies from the AV1 video encoding format. Both full and limited color gamut color spaces are supported, as well as transformation operations (rotation and mirroring). Animation is not yet supported. A parameter ‘image.avif.compliance_strictness’ has been proposed in about:config to configure specification compliance. The default value of the HTTP header ACCEPT has been changed to ‘image/avif,image/webp,*/*’.
  • The WebRender engine, written in Rust, has been made mandatory, allowing for a significant increase in rendering speed and a reduction in CPU load by offloading page content rendering operations, which are realized through shaders executed on the GPU. For systems with older graphics cards or problematic graphic drivers, WebRender applies a software rasterization mode (gfx.webrender.software=true). The option to disable WebRender (gfx.webrender.force-legacy-layers and MOZ_WEBRENDER=0) has been discontinued.
  • Improved support for the Wayland protocol. A layer has been added to address clipboard issues in environments based on the Wayland protocol. The update also includes changes that eliminate flickering when moving a window to the edge of the screen in multi-monitor configurations while using Wayland.
  • The built-in PDF viewer has implemented the ability to open documents with interactive XFA forms, commonly used in electronic forms from various banks and government institutions.
    Release of Firefox 93
  • File download protection is enabled for files delivered over HTTP without encryption but initiated from pages opened via HTTPS. Such downloads are vulnerable to tampering due to transit traffic control, yet since they originate from HTTPS pages, users may mistakenly feel they are secure. When attempting to download such data, users will receive a warning that allows them to cancel the block if they choose. Additionally, downloading files from isolated iframes without the allow-downloads attribute specified is now prohibited and will be silently blocked.
    Release of Firefox 93
  • The implementation of the SmartBlock mechanism has been improved to address issues on websites caused by the blocking of external scripts in private browsing mode or when enhanced tracking protection (strict) is activated. SmartBlock automatically replaces tracking scripts with placeholders that ensure the website loads correctly. The placeholders are tailored for several popular user tracking scripts listed in Disconnect. The new version includes adaptive blocking for Google Analytics scripts, Google ad network scripts, and widgets from Optimizely, Criteo, and Amazon TAM.
  • In private browsing modes and enhanced tracking protection (strict), additional protection for the HTTP header 'Referer' has been implemented. In these modes, websites are now prohibited from enabling the 'no-referrer-when-downgrade', 'origin-when-cross-origin', and 'unsafe-url' policies via the HTTP header Referrer-Policy, which allow bypassing default settings to send the full URL in the 'Referer' header to third-party sites. It should be noted that in Firefox 87, the policy 'strict-origin-when-cross-origin' was activated by default to prevent potential confidential data leaks, cutting out paths and parameters from 'Referer' when sending requests to other hosts over HTTPS, sending an empty 'Referer' when transitioning from HTTPS to HTTP, and sending the full 'Referer' for internal transitions within the same site. However, the effectiveness of this change was questioned, as sites could manipulate Referrer-Policy to restore old behavior.
  • The Windows platform now supports automatic unloading of tabs from memory when the free memory level in the system reaches critically low values. First, the tabs consuming the most memory and those that the user has not accessed for a long time are unloaded. When switching to an unloaded tab, its content is automatically reloaded. This functionality is promised to be added in a future release for Linux.
  • The design of the download panel has been aligned with the overall visual style of Firefox.
    Release of Firefox 93
  • In compact mode, the margins between the main menu elements, overflow menu, bookmarks, and browsing history have been reduced.
    Release of Firefox 93
  • SHA-256 has been added to the algorithms available for HTTP Authentication, previously only MD5 was supported.
  • TLS ciphers using the 3DES algorithm are disabled by default. For example, the TLS_RSA_WITH_3DES_EDE_CBC_SHA cipher suite is vulnerable to the Sweet32 attack. Support for 3DES can be restored by explicitly allowing it in the settings of older TLS versions.
  • On the macOS platform, a problem with session loss when starting Firefox from a mounted '.dmg' file has been resolved.
  • A user interface has been implemented for visual input of date and time for the web form element .
    Release of Firefox 93
  • For elements with the aria-label or aria-labelledby attribute, a meter role (role="meter") has been implemented, allowing for indicators of numerical values that change within a certain range (e.g., battery charge indicators).
    Release of Firefox 93
  • Support for the keyword "small-caps" has been added to the CSS property font-synthesis.
  • The method Intl.supportedValuesOf() has been implemented, returning an array of supported calendars, currencies, counting systems, and units of measurement.
  • Classes have been given the ability to use static initialization blocks to group code that runs once when the class is processed: class C { // Block will be executed when processing the class static { console.log("C's static block"); }}
  • Support for calling HTMLElement.attachInternals has been added for access to additional form management methods.
  • The attribute shadowRoot has been added to the ElementInternals method, allowing custom elements to access their separate root in the Shadow DOM, regardless of its state.
  • The createImageBitmap() method has added support for imageOrientation and premultiplyAlpha properties.
  • A global function reportError() has been added, allowing scripts to log errors to the console, simulating the occurrence of an uncatchable exception.
  • Improvements in the version for the Android platform:
    • When launched on tablets, forward, back, and reload buttons have been added to the panel.
    • Automatic filling of usernames and passwords in web forms is enabled by default.
    • Firefox can now be used as a password manager to fill in usernames and passwords in other applications (enabled via 'Settings' > 'Logins and passwords' > 'Autofill in other apps').
    • A page 'Settings' > 'Logins and passwords' > 'Saved Logins' > 'Add Login' has been added for manually adding credentials to the password manager.
    • A page 'Settings' > 'Data collection' > 'Studies and switch off' has been added, allowing users to opt out of experimental feature testing.

In addition to new features and bug fixes, Firefox 93 addresses 13 vulnerabilities, 10 of which are marked as critical. 9 vulnerabilities (grouped under CVE-2021-38500, CVE-2021-38501, and CVE-2021-38499) are caused by memory management issues, such as buffer overflows and accessing already freed memory areas. These issues could potentially allow an attacker to execute code when opening specially crafted pages.

The beta release of Firefox 94 features the implementation of a new service page 'about:unloads' where users can force unload specific tabs to reduce memory consumption without closing them (contents will be reloaded when switching back to the tab).

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster