Release of Firefox 102

The release of the web browser Firefox 102 has taken place. This version of Firefox 102 is categorized under the Extended Support Release (ESR) branch, with updates being issued over the course of the year. Additionally, an update for the previous ESR version 91.11.0 has been formed (with two more updates, 91.12 and 91.13, expected soon). The Firefox 103 branch is set to enter beta testing in the coming hours, with its release scheduled for July 26.

Key innovations in Firefox 102:

  • The option to disable the automatic opening of the downloads panel at the start of each new download has been provided.
    Release of Firefox 102
    Release of Firefox 102
  • Tracking protection when transitioning to other pages has been added by adjusting parameters in the URL. This protection involves removing tracking parameters from the URL (such as utm_source) and is activated when strict blocking of unwanted content is enabled in settings (Enhanced Tracking Protection -> Strict) or when the site is opened in private browsing mode. Selective cleaning can also be enabled via the parameter privacy.query_stripping.enabled in about:config.
  • Sound decoding functions have been moved to a separate process with stricter sandbox isolation.
  • In picture-in-picture mode, subtitles are now displayed when watching videos from HBO Max, Funimation, Dailymotion, Tubi, Disney+ Hotstar, and SonyLIV. Previously, subtitles were only shown for YouTube, Prime Video, Netflix, and sites utilizing the WebVTT format (Web Video Text Track).
  • On the Linux platform, the use of the DBus service Geoclue for determining location has been enabled.
  • PDF document viewing has been improved in high contrast mode.
  • In the web developer interface, the Style Editor tab now supports filtering style sheets by name.
    Release of Firefox 102
  • In the Streams API, the TransformStream class and the ReadableStream.pipeThrough method have been added, which can be used to create and transmit data as a stream (pipe) between ReadableStream and WritableStream, allowing a handler to be called for transforming the stream for each block.
  • In the Streams API, the ReadableStreamBYOBReader, ReadableByteStreamController, and ReadableStreamBYOBRequest classes have been added for efficient direct transfer of binary data bypassing internal queues.
  • The non-standard Window.sidebar property, which is provided only in Firefox, is slated for removal.
  • Integration of CSP (Content-Security-Policy) with WebAssembly is ensured, allowing CSP restrictions to be applied to WebAssembly as well. Now, a document that restricts script execution via CSP will not be able to run WebAssembly bytecode unless the ‘unsafe-eval’ or ‘wasm-unsafe-eval’ parameter is set.
  • In CSS media queries, the update property has been implemented, allowing binding to the refresh rate of the output device (for example, the value 'slow' is set for e-book screens, 'fast' for regular screens, and 'none' for print output).
  • For add-ons supporting the second version of the manifest, access to the Scripting API is provided, allowing scripts to be executed in the context of websites, CSS to be injected and removed, and management of content script registration.
  • In Firefox for Android, when filling out forms with credit card information, a separate request is now presented to save the entered information for the autofill system. The issue causing crashes when the on-screen keyboard is opened with a large amount of clipboard data has been resolved. The problem causing Firefox to stop when switching between applications has also been fixed.

In addition to new features and bug fixes, Firefox 102 addresses 22 vulnerabilities, of which 5 are marked as critical. Vulnerability CVE-2022-34479 allows a pop-up window to be displayed on the Linux platform, obscuring the address bar (which can be used to simulate a fake browser interface misleading the user, e.g., for phishing). Vulnerability CVE-2022-34468 allows circumventing CSP restrictions that prevent JavaScript execution in iframes by substituting 'javascript:' URI links. Five vulnerabilities (under CVE-2022-34485, CVE-2022-34486, and CVE-2022-34484) arise from memory management issues such as buffer overflows and access to freed memory areas. These issues could potentially lead to the execution of malicious code when opening specially crafted pages.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster