Firefox 88 Release

The release of the web browser Firefox 88 has taken place. Additionally, an update for the long-term support branch 78.10.0 has been formed. The Firefox 89 branch will soon enter the beta testing phase, with its release scheduled for June 1.

Key innovations:

  • The PDF viewer has added support for integrated input forms within PDF files, utilizing JavaScript for interactive user engagement.
  • A limit has been introduced on the intensity of permission requests for accessing the microphone and camera. Such requests will not display if the user has already granted access to the same device for the same site and tab within the last 50 seconds.
  • The screenshot tool has been removed from the 'Page Actions' menu, which appears when clicking the ellipsis in the address bar. To create screenshots, it is recommended to use the context menu tool accessed by right-clicking or to place a shortcut on the toolbar through the appearance settings interface.
    Firefox 88 Release
  • Support for pinch-to-zoom has been added on touchpads in Linux with graphical environments based on the Wayland protocol.
  • Localization of measurement units used for setting margins has been implemented in the printing system.
  • When launching Firefox in Xfce and KDE environments, the WebRender compositing engine has been activated. In Firefox 89, WebRender is expected to be enabled for all other Linux users, including all Mesa versions and systems with NVIDIA drivers (previously, WebRender was only enabled for GNOME with Intel and AMD drivers). WebRender is written in Rust and significantly increases rendering speed while reducing CPU load by offloading rendering operations to the GPU through executed GPU shaders. To force enable this, activate the 'gfx.webrender.enabled' setting in about:config or launch Firefox with the environment variable MOZ_WEBRENDER=1 set.
  • The phased activation of the HTTP/3 and QUIC protocols has begun. Initially, HTTP/3 support will be activated for only a small percentage of users and, barring any unforeseen issues, will be rolled out to all by the end of May. HTTP/3 requires support on the client side. server the same version of the draft standards for QUIC and HTTP/3, which is specified in the Alt-Svc header (Firefox supports draft specifications from 27 to 32).
  • FTP protocol support is disabled by default. The network.ftp.enabled setting is set to false by default, and the parameter for extensions browserSettings.ftpProtocolEnabled has been switched to read-only mode. All code related to FTP will be removed in the next release. The reason given is to reduce the risks of attacks on old code, which has a history of vulnerabilities and maintenance issues related to FTP support. There is also mention of eliminating protocols that do not support encryption, which are vulnerable to modification and interception of transit traffic during MITM attacks.
  • To block possible cross-site leaks, the value of the property "window.name" is isolated by the primary site from which the page is opened.
  • In JavaScript, a new property "indices" has been added to the results of regular expression executions, which contains an array of the starting and ending positions of matching groups. This property is populated only when a regular expression is executed with the flag "\/d". let re = \/quick\s(brown).+?(jumps)\/igd; let result = re.exec(‘The Quick Brown Fox Jumps Over The Lazy Dog’); \/\/ result.indices[0] === Array [ 4, 25 ] \/\/ result.indices[1] === Array [ 10, 15 ] \/\/ result.indices[2] === Array [ 20, 25 ]
  • In Intl.DisplayNames() and Intl.ListFormat(), the checks have been tightened to ensure that options passed to the constructor are objects. Attempting to pass strings or other primitives will raise exceptions.
  • A new static method AbortSignal.abort() is provided for the DOM, which returns an AbortSignal that has already been marked as aborted.
  • New pseudo-classes ":user-valid" and ":user-invalid" have been implemented in CSS, which define the validation state of a form element, for which validation of the specified values was performed after user interaction with the form. The key difference between ":user-valid" and ":user-invalid" and the pseudo-classes ":valid" and ":invalid" is that validation begins only after the user moves to another element (for example, by tabbing to another field).
  • The CSS function image-set(), which allows the selection of an image from a set of options with different resolutions that is most suitable for the current screen parameters and network bandwidth, can now be used in the CSS properties "content" and "cursor". h2::before { content: image-set( url("small-icon.jpg") 1x, url("large-icon.jpg") 2x); }
  • In the CSS property outline, the outline now conforms to the contour set by the border-radius property.
  • For macOS, the default monospace font has been changed to Menlo.
  • In the web development tools, a toggle has been added in the network inspection panel to switch between displaying HTTP responses in JSON format and unchanged format, in which responses are transmitted over the network.
    Firefox 88 Release
  • The default support for the AVIF image format (AV1 Image Format), which utilizes intra-frame compression technologies from the AV1 video encoding format, has been postponed to the next release. Firefox 89 is also expected to offer an updated user interface and integrate a calculator into the address bar (activated via suggest.calculator in about:config).

In addition to new features and bug fixes in Firefox 88, 17 vulnerabilities have been addressed, 9 of which are marked as critical. 5 vulnerabilities (gathered under CVE-2021-29947) are caused by memory handling issues, such as buffer overflows and accessing already freed memory areas. These issues could potentially lead to the execution of malicious code when opening specially crafted pages.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster