The release of the Firefox 103 web browser has taken place. Additionally, long-term support branches 91.12.0 and 102.1.0 have been updated. The Firefox 104 branch will enter beta testing in the coming hours, with a release scheduled for August 23.
Key Features in Firefox 103:
- By default, Total Cookie Protection is enabled, which was previously only applied when opening sites in private browsing mode and when choosing a strict mode for blocking unwanted content. In Total Cookie Protection mode, a separate isolated storage is applied for cookies from each website, preventing cookies from being used to track movement between sites, as all cookies set by third-party blocks (iframes, js, etc.) are tied to the site from which these blocks were loaded and are not passed when accessing these blocks from other sites.

- Performance has been improved on systems with high refresh rate monitors (120Hz+).
- The built-in PDF viewer now highlights required input fields for documents with forms.
- The picture-in-picture mode has added the ability to change the font size of subtitles. Subtitles are now displayed while watching videos on Funimation, Dailymotion, Tubi, Hotstar, and SonyLIV. Previously, subtitles were only displayed for YouTube, Prime Video, Netflix, HBO Max, Funimation, Dailymotion, Disney+, and sites that use the WebVTT (Web Video Text Track) format.
- Arrow keys, Tab, and Shift+Tab can now be used to navigate buttons on the tab bar.
- The text enlargement feature for visually impaired users ('Make text bigger') has been expanded to all interface elements and content (previously it only affected the system font).
- The option to revert support for digital signature certificates based on SHA-1 hashes, which have long been considered insecure, has been removed from the settings.
- When copying text from web forms, non-breaking spaces are preserved to prevent automatic line breaks.
- On the Linux platform, issues with WebGL performance when using proprietary NVIDIA drivers in combination with DMA-Buf have been resolved.
- A problem with very slow startup due to processing content in local storage has been fixed.
- The Streams API now supports transferable streams, allowing the transfer of ReadableStream, WritableStream, and TransformStream objects as arguments to the postMessage() call, enabling operation execution in a web worker with data cloning in the background.
- Access to the caches, CacheStorage, and Cache APIs is restricted for pages opened without HTTPS and from iframe blocks.
- Support for the scriptminsize and scriptsizemultiplier attributes, previously marked as deprecated, has been discontinued.
- In Windows 10 and 11, the Firefox icon is pinned to the taskbar during installation.
- On the macOS platform, a transition to a more modern API for managing locks has been made, improving interface responsiveness during high CPU load.
- The Android version has fixed a crash when entering split-screen mode or resizing the window. An issue that caused videos to play in reverse has been resolved. A bug that could lead to a crash when opening the on-screen keyboard under rare circumstances in the Android 12 environment has been corrected.
In addition to new features and bug fixes, Firefox 103 addresses 10 vulnerabilities, of which 4 are marked as critical (classified under CVE-2022-2505 and CVE-2022-36320) caused by memory management issues such as buffer overflows and accessing already freed memory areas. These problems can potentially allow for the execution of malicious code when specially crafted pages are opened. Among the vulnerabilities of moderate severity, there is the potential for cursor position detection through manipulation of CSS properties overflow and transform, as well as a hang in the Android version when handling very long URLs.
Source: opennet.ru

