Release of Firefox 147

The release of web browser Firefox 147 has taken place, and updates for previous long-term support branches — 140.7.0 and 115.32.0 — have been formed. The Firefox 148 branch has entered beta testing, with the release scheduled for February 24.

Key innovations in Firefox 147 (1, 2, 3):

  • Support for the Freedesktop.org XDG Base Directory specification has been added, along with the ability to use the directory ‘~/.config/mozilla’ for storing profiles, extensions, settings, and internal databases. Support for placing data in the older directory ‘~/.mozilla’ remains available as an option, activated by starting with the ‘MOZ_LEGACY_HOME=1’ environment variable.
  • Support for the ‘Compression Dictionary Transport’ mechanism (RFC 9842) has been added, allowing the size of data transmitted between the client and proxy server, by using compression algorithms Zstandard (Content-Encoding: dcz) and Brotli (Content-Encoding: dcb) in combination with the compression of typical structures using dictionaries. There are two usage scenarios for Compression Dictionary Transport — compressing content using dictionaries previously sent by the server and using previously sent content as a dictionary to compress its new version (delta compression, where only changes compared to the existing version are transmitted).

    For instance, when requesting ‘GET /index.html’, the server may provide information about the presence of a dictionary, returning its path in the header ‘Link: ; rel="compression-dictionary"’. When the client downloads the dictionary ‘…/dict’, the server will provide information about its application to HTML files, setting the header ‘Use-As-Dictionary: match="/*html"’. In the next HTML resource request, such as ‘GET /index2.html’, the client will indicate its possession of a dictionary through the header ‘Available-Dictionary: hash_dictionary’. If the server has a dictionary with the given hash, it will return the content of index2.html, compressed using that dictionary.

    For delta compression of different versions of JavaScript files in response to the request ‘GET /app.v1.js’, the server may set the header ‘Use-As-Dictionary: match="/app*js"’, indicating that the returned content can be used as a dictionary for paths ‘/app*js’. In the subsequent request for a file matching this pattern, such as ‘GET /app.v2.js’, the client will send the hash of the existing dictionary via the header ‘Available-Dictionary:’, and the server will return only the changes between the files app.v1.js and app.v2.js.

  • The about:keyboard page has been added for configuring keyboard combinations and overriding existing shortcuts, for example, to set more familiar options or to avoid conflicts with other programs.
    Release of Firefox 147
  • Video playback has been optimized using hardware acceleration for decoding on AMD GPUs. On systems with AMD GPUs, hardware-decoded video now plays without additional data copying (zero-copy mode), as was previously implemented for systems with Intel and NVIDIA GPUs.
  • For version 5, the implementation of the Safe Browsing protocol, used to check URLs against lists of unsafe resources (phishing sites, malware pages, etc.) provided by Google, has been updated. The new version of the protocol allows downloading blocklists for use on the local system (a database with SHA256 hash prefixes of problematic URLs), which are now implemented in Firefox.
  • An option has been added for automatic video playback continuation in picture-in-picture mode when switching tabs.
  • In Enhanced Tracking Protection (ETP => Strict) mode, the application of the LNA (Local Network Access) specification is enabled by default to restrict access to the local system (loopback, 127.0.0.0/8) or internal network (192.168.0.0/16, 10.0.0.0/8, etc.) when interacting with public websites. Accessing internal resources is exploited by attackers to carry out CSRF attacks on routers, access points, printers, corporate web interfaces, and other devices and services that accept requests only from the local network. Additionally, scanning internal resources can be used for indirect identification or gathering information about the local network.
  • On Linux systems with GNOME and the Mutter compositor, an issue with content appearing blurred when using fractional scaling has been resolved.
  • Support for the WebGPU API has been added on Apple computers with Apple Silicon chips and macOS.
  • The language selection priorities (q-parameters) specified in the HTTP header Accept-Language are synchronized with the values set by other browsers, resolving some compatibility issues. For example, the priority for the second language is now set to q=0.9 instead of q=0.5, and for each subsequent language, the priority decreases by 0.1.
  • The ICU library has been updated to version 78 with support for Unicode 17 and locale data updates.
  • Service Workers now allow the use of ESM (ECMAScript Module) JavaScript modules, imported and exported through import and export statements.
  • Support for the CSS Module Scripts specification has been added, enabling the JavaScript module system to import CSS resources. For example: import styles from './styles.css' with { type: 'css' };
  • In the pseudo-element '::marker', which allows customization of number and bullet styles for lists in
      and
        blocks, the CSS properties 'counter-*' and 'quotes' are now permitted.
      1. The CompressionStream and DecompressionStream APIs have added support for the Brotli compression format.
      2. In the View Transitions API, used for creating animation effects when switching between different DOM states, a 'type' property has been added that contains an array of transition types. A corresponding CSS selector ':active-view-transition-type' and the property document.activeViewTransition, which returns an instance of the active ViewTransition object for the document, have also been added.
      3. A set of CSS properties has been introduced for controlling the display of elements linked to the positions of other elements (CSS Anchor Positioning) without using JavaScript, for example, to attach popover elements that appear similarly to tooltips.
      4. The 'Storage Access Headers' specification has been implemented, defining the request header 'Sec-Fetch-Storage-Access' and the response header 'Activate-Storage-Access' to access third-party cookies without calling the method document.requestStorageAccess(). The server can request access to cookies via the 'Activate-Storage-Access' header, which will be sent by the client if the user previously confirmed granting access to the cookie storage through the Storage Access API.
      5. Support for the relative measurement units rcap, rch, rex, and ric has been added to the CSS property 'root-font-relative'.
      6. The Navigation API has been implemented, allowing web applications to intercept navigation operations in the window, initiate transitions, and analyze the history of actions with the application. The API provides an alternative to window.history and window.location properties, optimized for single-page web applications.
      7. In the web development tools, support for editing and adding pseudo-element selectors has been implemented in the CSS rules panel. A button has been added to the interface for viewing data in JSON format for importing resources into the profiling system (Firefox Profiler) to determine information about their size. The inspection panels for HTML elements and animations now display pseudo-elements during View Transitions. The CSS rules panel now shows @position-try rules used to control the display of elements tied to the location of other elements (CSS Anchor Positioning).
      8. In the Firefox version for Android, it has been added protection against attacks through third-party channels, such as Spectre, which are used to bypass site isolation. Previously, such protection was only available in desktop builds.

    In addition to new features and bug fixes, Firefox 147 has resolved 23 vulnerabilities. Ten vulnerabilities were caused by memory management issues, such as buffer overflows and access to already freed memory areas. These issues could potentially lead to the execution of attacker code when opening specially crafted pages. Three vulnerabilities allow bypassing sandbox isolation due to improper boundary checks and integer overflows in the graphics handling component.

    Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster