A corrective release of Firefox 146.0.1 is available, which fixes 3 vulnerabilities caused by accessing already freed memory areas (CVE-2025-14860) and buffer overflows (CVE-2025-14861). These issues could potentially lead to the execution of malicious code when opening specially crafted pages. Additionally, several non-security-related issues have been resolved:
- Increased text contrast in the sidebar when using vertical tabs (some themes showed dark letters on a dark background).
- Three issues leading to crashes have been resolved (1, 2, 3).
- Fixed an issue in the implementation of protection against browser fingerprinting, which led to a misdisplay of fonts on some popular sites, including Instagram, Facebook, X, and YouTube.
- Crashes that occurred during multimedia content playback and when finishing the GMP (Gecko Media Plugin) process have been resolved.
- Fixed a bug that caused the deletion of profile shortcuts after changing the settings of copied profiles.
- The message about successful restoration from backup now appears on the new tab page (about:newtab), rather than on one of the restored tabs.
Additionally, Mozilla representatives have responded to criticism regarding the announcement of transforming Firefox into an AI browser. Anthony Enzor-DeMeo, head of Mozilla Corporation, confirmed that Firefox will remain fully user-controlled and will provide the option to disable AI. This feature will be added in Q1 2026.
Jake Archibald, who is responsible for developer relations at Mozilla, stated that AI functionality will only be enabled at the user's request (opt-in), likely via a button located on the toolbar. An 'AI kill switch' option will also be provided to completely disable all AI-related capabilities. After activating this option, all AI functionalities will be removed and will not be displayed further.
Source: opennet.ru
