Release of Firefox 109

The release of the web browser Firefox 109 has occurred. Additionally, an update for the long-term support branch — 102.7.0 — has been created. The Firefox 110 branch will soon enter the beta testing phase, with a release scheduled for February 14.

Key innovations in Firefox 109:

  • By default, support for the third version of the Chrome manifest is enabled, which defines the capabilities and resources available for extensions written using the WebExtensions API. Support for the second version of the manifest will be maintained in the foreseeable future. Since the third version of the manifest has come under criticism and will lead to the malfunctioning of some extensions for blocking unwanted content and ensuring security, Mozilla has moved away from providing full compatibility with the manifest in Firefox and has implemented some features differently. For example, support for the legacy blocking mode of the webRequest API has not been discontinued, whereas a new declarative content filtering API has replaced it in Chrome. Additionally, support for the granular permission request model has been implemented somewhat differently, in accordance with which an extension cannot be activated right away for all pages (the

    Release of Firefox 109
  • The Firefox View page has improved the layout of empty sections with recently closed tabs and tabs that are open on other devices.
  • The list of recently closed tabs displayed on the Firefox View page has added buttons for removing individual links from the list.
    Release of Firefox 109
  • The ability to display the entered search query in the address bar has been added, instead of showing the search engine's URL (i.e., the keys are shown in the address bar not only during input but also after querying the search engine and displaying the results related to the entered keys). This feature is currently disabled by default and requires setting the configuration 'browser.urlbar.showSearchTerms.featureGate' in about:config to activate.
    Release of Firefox 109
  • The date picker dialog for the fields with types 'date' and 'datetime' has been adapted for keyboard control, ensuring proper support for screen readers and allowing keyboard shortcuts for calendar navigation.
  • The experiment with the built-in Colorways extension for changing the browser's appearance has concluded (a collection of color themes for the content area, panels, and tab switching bar was offered). Access to previously saved color themes can be found on the 'Add-ons and themes' page.
  • On systems with GTK, the ability to move multiple files simultaneously within the file manager has been implemented. The moving of images from one tab to another has been streamlined.
  • In the automatic clicking system for banners requesting cookie usage permissions on websites (cookiebanners.bannerClicking.enabled and cookiebanners.service.mode in about:config), the option to add websites to an exceptions list for which auto-clicking does not apply has been implemented.
  • By default, the setting network.ssl_tokens_cache_use_only_once is enabled to prevent the reuse of session tickets in TLS.
  • The setting network.cache.shutdown_purge_in_background_task has been enabled, addressing the issue of correctly terminating file input/output when shutting down.
  • A new item ('Pin to toolbar') has been added to the context menu of extensions for pinning the extension button to the toolbar.
  • Firefox can now be used as a document viewer, selected in the system through the context menu 'Open With'.
  • Information about screen refresh rates has been added to the about:support page.
  • Settings for ui.font.menu, ui.font.icon, ui.font.caption, ui.font.status-bar, ui.font.message-box, etc., have been added to override system fonts.
  • By default, support for the scrollend event is enabled, generated when the user stops scrolling (when the position ceases to change) in Element and Document objects.
  • Access partitioning through the Storage API is provided when processing third-party content, regardless of the Storage Access API.
  • The range element has been updated to support the list attribute, which passes the ID of the element containing a list of predefined values suggested for input.
  • The CSS property content-visibility, used to exclude unnecessary rendering of areas outside the viewport, has been given the 'auto' value, which allows the browser to determine visibility based on the proximity of the element to the visible area boundary.
  • In the CSS type , which defines default values for the colors of various page components, support has been added for Mark, MarkText, and ButtonBorder values.
  • Web Auth now supports authentication using the CTAP2 (Client to Authenticator Protocol) protocol with tokens based on USB HID. Support is not enabled by default and can be activated with the security.webauthn.ctap2 parameter in about:config.
  • In developer tools, the JavaScript debugger has added a new breakpoint type that triggers upon entry to the scrollend event handler.
  • The remote browser control protocol WebDriver BiDi has added support for the 'session.subscribe' and 'session.unsubscribe' commands.
  • Windows builds now include the use of the ACG (Arbitrary Code Guard) hardware protection mechanism to block exploits in processes that handle multimedia content playback.
  • On macOS, the behavior of the Ctrl/Cmd + trackpad or Ctrl/Cmd + mouse wheel combinations has been changed to scroll (as in other browsers), rather than zoom.
  • Improvements in the Android version:
    • When viewing fullscreen video, the address bar is disabled during scrolling.
    • A button has been added to undo changes after a pinned site has been removed.
    • The search engine list is updated after changing the language.
    • A crash occurring when a large chunk of data is placed in the clipboard or address bar has been resolved.
    • The performance of canvas element rendering has been improved.
    • An issue with video calls, which could only use the H.264 codec, has been resolved.

In addition to new features and bug fixes, Firefox 109 closes 21 vulnerabilities. Of these, 15 are classified as critical, with 13 of them (identified as CVE-2023-23605 and CVE-2023-23606) caused by memory management issues, such as buffer overflows and accessing freed memory areas. These issues could potentially allow an attacker to execute code when visiting specially crafted pages. The vulnerability CVE-2023-23597 is due to a logical error in the code for creating new child processes, allowing a new process to be launched in the file:// context to read arbitrary file contents. The vulnerability CVE-2023-23598 stems from an error in handling drag-and-drop actions in the GTK wrapper and allows reading arbitrary file contents through a DataTransfer.setData call.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster