Firefox 145 release with enhanced protection against hidden tracking

The release of the Firefox 145 web browser has taken place, along with updates for the long-term support branches — 140.5.0 and 115.30.0. The Firefox 146 branch is now in beta testing, with its release scheduled for December 9.

Key innovations in Firefox 145 (1, 2, 3):

  • Support for 32-bit Linux systems has been discontinued. It is noted that maintaining Firefox on 32-bit platforms is becoming increasingly difficult and unreliable, especially since support for 32-bit builds has already been discontinued in most Linux distributions. Users of 32-bit Linux distributions are advised to switch to 64-bit operating systems. For those who cannot promptly update their distribution, the ESR branch of Firefox 140 can be used, with security updates provided at least until September of the following year.
  • Button, tab, address bar, and input field rounding has been enhanced.
    Firefox 145 release with enhanced protection against hidden tracking
  • The built-in PDF viewer now supports adding, editing, and deleting comments/annotations. A separate sidebar has been added for navigating and viewing existing comments. While adding a comment, you can choose a color for highlighting it on the background.
    Firefox 145 release with enhanced protection against hidden tracking
  • Hovering over the label of a collapsed tab group now displays a list of tabs in the group, allowing quick access to the desired tab without needing to expand the entire group first.
    Firefox 145 release with enhanced protection against hidden tracking
  • It's now possible to manage saved passwords directly from the sidebar without needing to open the password manager in a separate window or tab.
    Firefox 145 release with enhanced protection against hidden tracking
  • A new collection of background images for the new tab page has been introduced, available in both light and dark mode versions.
    Firefox 145 release with enhanced protection against hidden tracking
  • A new option has been added to the tab settings that allows placing the tab created when opening links from external applications next to the currently active tab, rather than at the end of the tab list.
    Firefox 145 release with enhanced protection against hidden tracking
  • The context menu has been enhanced with the 'Copy Link to Highlight' option, which allows users to create a link that points to a section of text highlighted on the page. Links to the selected text use the format 'https://www.example.com #:~:text=mask'.
  • The capabilities of the Fingerprinting Protection mode, used when Enhanced Tracking Protection (ETP, Enhanced Tracking Protection => Strict) is enabled or when opening pages in private browsing mode, have been expanded. It is noted that the changes made nearly halve the effectiveness of hidden identification methods compared to the previously existing protection.

    To enhance protection, constant values have been returned for parameters that may serve as additional traits for identification, and access to equipment details, such as the number of simultaneous touches supported by the touchpad and the number of processor cores, has been restricted. Noise substitution has been implemented when attempting to read from image scripts generated via the canvas element. Rendering text on the page with locally installed custom fonts has been disabled.

    Firefox 145 release with enhanced protection against hidden tracking
  • In the enhanced protection mode (strict) for Enhanced Tracking Protection (ETP), protection against tracking through redirects (Bounce Tracking Protection) is enabled by default. The Bounce Tracking Protection mechanism captures activity specific to tracking via redirects and periodically clears cookies and locally stored data used for tracking. Unlike the 'Cookie Purging' mode, the clearing is not based on a list of known trackers, but on heuristics that allow the identification of new tracker sites by analyzing behavior after a redirect.

    The essence of redirect-based tracking is that the tracker's code first redirects the user to its site and then forwards them to the target page, allowing the tracker to save cookies and data in local storage tied to its site. Retaining data after transitioning to another site allows the previously implemented methods in the browser to block cross-site operations to be bypassed — as the intermediary page opens outside the context of the other site, tracking cookies can be established freely on that page.

  • Support for Matroska containers (for codecs AVC, HEVC, VP8, VP9, AV1, AAC, Opus, and Vorbis) has been added.
  • In the built-in machine translation system, the convenience of translating between languages with different character direction has been improved. The Zstandard algorithm has been employed to compress locally installed models, reducing the size of downloaded data and saving space on the local storage.
  • In configurations without installed extensions, clicking the panel button for accessing extensions now shows an explanation of the benefits of extensions with a link to the extensions catalog.
  • JavaScript has implemented the method Atomics.waitAsync(), which offers an asynchronous version of the Atomics.wait() method, allowing it to wait for the location of the SharedArrayBuffer similarly to Atomics.wait(), but returning a Promise.
  • Support has been added for the HTTP headers Integrity-Policy and Integrity-Policy-Report-Only, which can be used to verify the integrity of loaded scripts.
  • The CSS property text-autospace has been implemented, performing automatic adjustments to the spacing between characters from different writing systems (for example, between Latin characters and hieroglyphs).
  • The CSS property font-family has implemented support for the 'math' font family for accurate rendering of mathematical expressions.
  • The ToggleEvent API has added a source property that contains the Element object representing the control element that initiated the state change that generated the Toggle event. For instance, when a user clicks on the '
  • In builds for the Windows platform, the shortcut to launch Firefox has been replaced with a separate mini-application (launcher) that starts Firefox if it is already installed or launches the installer if it is not yet on the system.
  • On Apple computers with Apple Silicon chips and macOS 26, support for the WebGPU API has been implemented.
  • In Firefox for Android:
    • Mandatory verification has been enabled for TLS certificates of web servers in public Certificate Transparency logs, designed to identify certificates created outside standard processes by a certificate authority (for example, covertly creating a certificate as a result of employee abuse or compromise of the certificate authority).
    • To speed up the revocation check of TLS certificates, the CRLite mechanism operating on the user's system has been employed. The user-side database containing information on certificates is periodically synchronized with an external Mozilla database.
    • Support for the hybrid key exchange algorithm 'mlkem768x25519' has been added for TLS 1.3 and HTTP/3, which is resistant to quantum computer attacks and consists of a combination of X25519 ECDH and the ML-KEM algorithm (CRYSTALS-Kyber).
    • The network stack components for the QUIC and HTTP/3 protocols have been replaced with an implementation written in Rust, which is characterized by improved performance. high performance.

In addition to new features and bug fixes, Firefox 145 has addressed 19 vulnerabilities. Ten of these vulnerabilities are caused by memory management issues, such as buffer overflows and access to freed memory areas. These problems could potentially allow an attacker to execute code when opening specially crafted web pages.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster