❌

Normale weergave

v0.20.0-rc.1

5 Juli 2026 om 07:55

❗ This is a pre-release

  • May contain bugs and unfinished features.

⚠️ Note for macOS users

Builds are unsigned (no Apple Developer ID). After dragging MarkText into Applications, clear the quarantine flag once:

xattr -cr /Applications/marktext.app

Verifying downloads

All artifacts are listed with their SHA-256 in SHA256SUMS.txt. Verify with:

sha256sum -c SHA256SUMS.txt --ignore-missing

What's Changed

  • fix(desktop): resolve Homebrew/standard bin dirs for GUI launches by @Jocs in #4796
  • fix(muya): show and slug TOC headings by rendered plain text (#3516) by @Jocs in #4811
  • Add UKey Wallet sponsor to README and website by @Jocs in #4819
  • fix(desktop): apply editor max-width preference to @muyajs/core content column (#4828) by @Jocs in #4830
  • Add Bengali README and links by @FahimFBA in #4823
  • fix(muya): skip identity operations during deferred flush by @tech-hoon in #4815
  • fix(muya): harden History against identity (null) json-change ops by @Jocs in #4838
  • fix(muya): stop inline math showing a scrollbar for trailing sub/superscripts (#4837) by @Jocs in #4839
  • fix(muya): isolate mermaid render failures during export (#4812) by @Jocs in #4840
  • fix(desktop): correct English typos in locale and preference schema (#4787) by @Jocs in #4845
  • fix(muya): stop double percent-encoding autolink hrefs by @Jocs in #4841
  • fix(muya): keep pasted list items in order when merging mid-list by @Jocs in #4842
  • fix(desktop): confirm before opening executable link targets (code execution) by @Jocs in #4843
  • fix(muya): keep soft line breaks when exporting to HTML/PDF by @Jocs in #4844
  • fix(muya): show escaped pipe in table cell code as | not | (#4849) by @Jocs in #4850
  • fix(muya): preserve fenced code block info string on round-trip (#4770) by @Jocs in #4846
  • fix(muya): load Prism component dependencies in order (fixes flaky c++ load) by @Jocs in #4861
  • refactor(muya): treat the code fence info string as the source of truth (CommonMark) by @Jocs in #4856
  • fix(muya): call h1-h6 "headings" not "headers" in the insert menu by @Jocs in #4854
  • fix(desktop): don't crash on unwatchable image directories (UNC/WSL paths) by @Jocs in #4853
  • fix(desktop): save files atomically to prevent data loss on crash by @Jocs in #4852
  • fix(desktop): make crash-recovery buffer writes durable against power loss by @Jocs in #4864
  • fix(muya): render extensionless remote images served with a charset (shields.io badges) by @Jocs in #4857
  • fix(muya): follow the link when modifier-clicking a linked image by @Jocs in #4858
  • fix(muya): follow the link on Ctrl/Cmd-click for reference-linked and raw-HTML linked images (#4865) by @Jocs in #4866
  • fix(desktop): keep TOC collapse state across tab switches by @Jocs in #4860
  • fix(desktop): flush pending edits before saving (dropped last keystroke) by @Jocs in #4859

New Contributors

Full Changelog: v0.20.0-beta.5...v0.20.0-rc.1

  •  

v0.20.0-beta.5

2 Juli 2026 om 16:54

❗ This is a pre-release

  • May contain bugs and unfinished features.

⚠️ Note for macOS users

Builds are unsigned (no Apple Developer ID). After dragging MarkText into Applications, clear the quarantine flag once:

xattr -cr /Applications/marktext.app

Verifying downloads

All artifacts are listed with their SHA-256 in SHA256SUMS.txt. Verify with:

sha256sum -c SHA256SUMS.txt --ignore-missing

What's Changed

  • fix(muya): scroll wide math blocks instead of clipping by @Jocs in #4751
  • fix(desktop): route undo/redo to CodeMirror in source code mode by @Jocs in #4752
  • fix(muya): leave Tab to the IME during composition by @Jocs in #4753
  • fix(desktop): add a context menu to the sidebar root folder by @Jocs in #4754
  • fix(muya): preserve code fence length on serialize by @Jocs in #4755
  • fix(muya): refresh math/diagram preview on undo by @Jocs in #4756
  • fix(desktop): resolve relative local links on export by @Jocs in #4757
  • fix(muya): require a word boundary before an emoji shortcode by @Jocs in #4758
  • fix(desktop): don't overwrite an existing file when creating from the sidebar by @Jocs in #4759
  • fix(desktop): ignore content-identical file-change events by @Jocs in #4760
  • fix(desktop): make the source-mode selection visible on dark themes by @Jocs in #4771
  • fix(desktop): persist export dialog options across sessions by @Jocs in #4768
  • fix(muya): convert $$ to a math block in place inside a list item by @Jocs in #4767
  • fix(muya): self-close generated tags for JSX/MDX compatibility by @Jocs in #4766
  • fix(muya): preserve current-line indent on Enter in code fences by @Jocs in #4761
  • fix(muya): make autolinks and bare URLs followable on Cmd/Ctrl-click by @Jocs in #4763
  • fix(muya): exclude selection whitespace when applying inline format by @Jocs in #4762
  • fix(desktop): make empty-state CTA button labels readable in all themes by @Jocs in #4775
  • fix(muya): surface the KaTeX parse error for invalid math by @Jocs in #4764
  • fix(desktop): keep sidebar width + tree collapse state across icon toggle by @Jocs in #4769
  • fix(muya): recognize c++/h++ as aliases for the cpp code grammar by @Jocs in #4794
  • fix(muya): don't highlight LaTeX \% as a comment by @Jocs in #4795
  • fix(muya): recolor sequence-diagram text/boxes for dark themes by @Jocs in #4800
  • fix(muya): keep image resize handles attached on layout reflow by @Jocs in #4802
  • fix(muya): make cpp c++/h++ alias registration idempotent by @Jocs in #4816
  • fix(desktop): preserve TOC collapse state across content edits by @Jocs in #4803
  • fix(desktop): make Paragraph/Format commands inert in source mode (grey out menus) by @Jocs in #4810
  • fix(desktop): New File on a collapsed sidebar folder expands it by @Jocs in #4809
  • fix(desktop): select the query when re-opening the Find bar by @Jocs in #4807
  • fix(desktop): keep diagram content when exporting with Header & Footer by @Jocs in #4805
  • fix(desktop): list bundled fonts in the font picker by @Jocs in #4801
  • fix(desktop): remove doubled Edit-menu separator on Windows/Linux by @Jocs in #4797
  • fix(desktop): generate a PDF outline from headings on export by @Jocs in #4798
  • fix(desktop): avoid PDF/print page breaks right after a heading by @Jocs in #4799

Full Changelog: v0.20.0-beta.4...v0.20.0-beta.5

  •  

v0.20.0-beta.4

26 Juni 2026 om 19:04

❗ This is a pre-release

  • May contain bugs and unfinished features.

⚠️ Note for macOS users

Builds are unsigned (no Apple Developer ID). After dragging MarkText into Applications, clear the quarantine flag once:

xattr -cr /Applications/marktext.app

Verifying downloads

All artifacts are listed with their SHA-256 in SHA256SUMS.txt. Verify with:

sha256sum -c SHA256SUMS.txt --ignore-missing

What's Changed

  • fix(renderer): keep the key bindings hover row readable on dark themes by @FurkaanBoraa in #4719
  • fix(renderer): make the custom dictionary table readable on dark themes by @FurkaanBoraa in #4721
  • feat(muya): self-contained editor typography via --mu-* options by @Jocs in #4722
  • refactor(desktop): consume muya self-contained typography, remove shell style injection by @Jocs in #4726
  • fix(muya): move preview toolbar to the block's top-right by @Jocs in #4734
  • fix(renderer): hide muya float tools in source-code mode by @Jocs in #4732
  • fix(desktop): remove duplicate title when using the native title bar by @Jocs in #4630
  • fix(muya): keep a nested sublist when forward-deleting an empty list item (#1845) by @Jocs in #4725
  • fix(muya): remove the inner format when un-toggling a nested inline run (#2063) by @Jocs in #4727
  • docs: add commenting guidelines by @Jocs in #4738
  • fix(muya): escape parentheses in inserted image paths (#3060) by @Jocs in #4728
  • fix(muya): decode HTML entities in fetched page titles when pasting a URL (#2525) by @Jocs in #4729
  • fix(muya): reset search state when the document is replaced (#1932) by @Jocs in #4730
  • fix(muya): split on Enter over a cross-block selection (#2443) by @Jocs in #4735
  • fix(muya): let Enter replace a selection when the format toolbar is shown (#3196) by @Jocs in #4736
  • fix(muya): stop punctuation after a link wrapping to its own line (#2258, #3025) by @Jocs in #4737
  • chore: audit Claude-authored comments against the commenting guidelines by @Jocs in #4740
  • fix: normalize HTML task-list paste by @Renakoni in #4710
  • fix: preserve bare URL HTML links on paste by @Renakoni in #4711
  • fix: preserve whitespace-only plain text paste by @Renakoni in #4706
  • fix: preserve nested HTML lists under ordered parents by @Renakoni in #4709
  • fix: prevent nested empty list items from becoming setext headings by @Renakoni in #4697
  • fix: preserve empty task list items when parsing markdown by @Renakoni in #4696
  • fix: remove ~1s sidebar delay for newly created files (#3955) by @Jocs in #4744
  • fix(i18n): degrade malformed translations to raw text instead of crashing (#4046) by @Jocs in #4745
  • fix: vertically center task list checkbox with item text by @Jocs in #4750
  • fix(desktop): prefer UTF-8 when a file is valid UTF-8 instead of trusting ced (#3151) by @Jocs in #4739
  • fix(desktop): scroll the view up when the caret moves above the viewport (#3329) by @Jocs in #4742
  • fix: scroll the active tab into view on tab switch (#3958) by @Jocs in #4743

Full Changelog: v0.20.0-beta.3...v0.20.0-beta.4

  •  

v0.20.0-beta.3

25 Juni 2026 om 17:19

❗ This is a pre-release

  • May contain bugs and unfinished features.

⚠️ Note for macOS users

Builds are unsigned (no Apple Developer ID). After dragging MarkText into Applications, clear the quarantine flag once:

xattr -cr /Applications/marktext.app

Verifying downloads

All artifacts are listed with their SHA-256 in SHA256SUMS.txt. Verify with:

sha256sum -c SHA256SUMS.txt --ignore-missing

What's Changed

  • fix(desktop): restore vue-tsc typecheck (vite 7 PluginOption) by @Jocs in #4667
  • fix(release): support immutable releases (draft-then-promote) + docs by @Jocs in #4666
  • fix(muya): undo/redo corruption on coalesced paragraphβ†’list + text edits by @Jocs in #4669
  • fix(renderer): keep find-bar prefill from being clobbered on open by @NSO73 in #4646
  • fix(muya): preserve nested-list indentation in RTL mode by @Jocs in #4676
  • fix(muya): load mhchem onto the same katex instance so \ce renders (#4670) by @Jocs in #4674
  • fix(muya): keep inline links that are followed by a bare URL or text (#4671) by @Jocs in #4672
  • fix(keybinding): sync menu bar and command palette when keybindings change by @Jocs in #4681
  • fix(muya): guard detached code block in language selector (#4654) by @Jocs in #4677
  • test(e2e): stabilize flaky search-prefill test (wait for selection commit) by @Jocs in #4682
  • fix: export PDF/HTML/print in the editor's text direction (RTL) by @Jocs in #4678
  • fix(muya): create a code-block when typing ``` + Enter inside block-quotes and lists by @Jocs in #4689
  • fix(muya): prevent undo/redo exceptions from permanently disabling history (#4685) by @Jocs in #4692
  • fix(muya): auto-hide inline markers when holding an arrow key out of a token by @Jocs in #4694
  • test(e2e): replace fixed waits with expect.poll in editor-input by @NSO73 in #4695
  • fix: normalize first-row colspan table paste by @Renakoni in #4707
  • fix(renderer): use the theme text colour for the key bindings list (#3937) by @FurkaanBoraa in #4713
  • fix: wrap selected text when typing auto-pair characters by @Renakoni in #4698
  • fix(muya): skip empty sibling containers in caret navigation (#4644 follow-up) by @FurkaanBoraa in #4715
  • fix(muya): stop the paragraph front-menu from acting on a stale block (#4686) by @Jocs in #4714
  • fix(muya): re-sync the live tree from json state when an undo/redo apply throws by @Jocs in #4717
  • fix(desktop): paint the launch window in the active theme's background (#3957) by @FurkaanBoraa in #4718

New Contributors

Full Changelog: v0.20.0-beta.2...v0.20.0-beta.3

  •  

v0.20.0-beta.2

23 Juni 2026 om 17:57

❗ This is a pre-release

  • May contain bugs and unfinished features.

⚠️ Note for macOS users

Builds are unsigned (no Apple Developer ID). After dragging MarkText into Applications, clear the quarantine flag once:

xattr -cr /Applications/marktext.app

Verifying downloads

All artifacts are listed with their SHA-256 in SHA256SUMS.txt. Verify with:

sha256sum -c SHA256SUMS.txt --ignore-missing

What's Changed

  • chore(release): v0.19.0 release branch (DO NOT MERGE until stable) by @Jocs in #4269
  • chore: bump develop to 0.20.0-dev by @Jocs in #4296
  • docs(release): update Step 7 asset list to 24 by @Jocs in #4298
  • docs(end-user): align user docs with 0.19 prefs and platform matrix by @Jocs in #4300
  • docs(dev): sync developer docs with current codebase by @Jocs in #4299
  • chore: convert repo to pnpm monorepo (packages/desktop, muyajs, website) by @Jocs in #4302
  • refactor(website): migrate to Next.js 15 + Cloudflare Workers CI by @Jocs in #4305
  • feat(website): serve www.marktext.me (301 β†’ apex) by @Jocs in #4308
  • fix(website): wwwβ†’apex redirect (middleware) + smarter preview-URL parsing by @Jocs in #4309
  • ci(website): enable Preview URLs on marktext-website Worker by @Jocs in #4311
  • refactor(website): redesign landing page, drop markdown engine deps by @Jocs in #4312
  • feat(muya): migrate TS rewrite to packages/muya alongside legacy muyajs by @Jocs in #4314
  • feat(website): add /docs route and consolidate docs/ under packages/website/ by @Jocs in #4316
  • fix: replace remaining absolute raw.githubusercontent.com URLs with relative paths in READMEs by @Jocs with @Copilot in #4329
  • fix(website): serve prerendered docs pages via static-assets cache by @Jocs in #4335
  • fix(website): open download buttons in new tab pointing to releases page by @Jocs in #4336
  • refactor(website): simplify docs subtree (palette / sidebar / markdown / nav) by @Jocs in #4349
  • refactor(website): simplify landing page (helpers, types, data-driven blocks) by @Jocs in #4350
  • chore(website): tighten middleware matcher; drop unused 'use client' by @Jocs in #4351
  • fix(muyajs): preserve nested lists of differing types (#4341) by @Jocs in #4354
  • fix(muyajs): allow CJK ideographs as flanking boundary for emphasis by @Jocs in #4355
  • fix(muyajs): clamp setStart offset to legal range to prevent IndexSizeError (#2800) by @Jocs in #4358
  • fix(muyajs): null-guard list block paths to prevent renderer crash (#4346) by @Jocs in #4359
  • fix: restore local builds after monorepo split by @Jocs in #4361
  • fix(release): add repository field for electron-builder by @Jocs in #4368
  • fix(muyajs): split correct paragraph on Enter in multi-block list items (#4374) by @Jocs in #4376
  • fix(renderer): improve graphite contrast and unify accent colors (#4377) by @Jocs in #4378
  • feat(muya): expose desktop-required public API accessors by @Jocs in #4381
  • feat(muya): expose themeable CSS variables and diagram theming by @Jocs in #4382
  • feat(muya): add block duplicate/insert/delete public API by @Jocs in #4384
  • feat(muya): restore flowchart and sequence diagrams by @Jocs in #4385
  • feat(muya): add ImagePathPicker floating autocomplete UI by @Jocs in #4386
  • fix(muya): unbreak lint:css (stylelint 17 compatibility) by @Jocs in #4388
  • feat(muya): add cursorCoords + active formats to selection-change by @Jocs in #4387
  • feat(muya): implement focus mode (dim inactive blocks) by @Jocs in #4389
  • feat(muya): emit format-click and preview-image interaction events by @Jocs in #4390
  • feat(muya): add updateParagraph block-type conversion API by @Jocs in #4391
  • feat(muya): add runtime setOptions / setFont / setTabSize / setListIndentation by @Jocs in #4393
  • feat(muya): add spellcheck word-replacement API by @Jocs in #4392
  • feat(muya): serialize/restore undo history by @Jocs in #4394
  • feat(muya): add invalidateImageCache by @Jocs in #4396
  • test(muya): port MarkText regression cases (#4341/#4307/#4190) by @Jocs in #4399
  • feat(muya): add createTable / insertImage / setCursor API by @Jocs in #4397
  • feat(muya): add clipboardFilePath paste hook by @Jocs in #4398
  • fix(muya): treat CJK as punctuation for strong/em flanking (#4307) by @Jocs in #4401
  • feat(desktop): consume @muyajs/core in util files (markdownToHtml/pdf/dompurify/printService/sourceCode/icon) by @Jocs in #4402
  • feat(desktop): add kebab-case editor CSS vars to themes for @muyajs/core by @Jocs in #4404
  • feat(desktop): migrate editor.vue to @muyajs/core engine by @Jocs in #4406
  • fix(i18n): unify quick-insert hint to "/" trigger by @Jocs in #4405
  • test(parity): failing-test scoreboard for #4406 muyajsβ†’@muyajs/core gaps by @Jocs in #4407
  • fix(muya): insertParagraph immediate-block anchoring in nested blocks (PG13) by @Jocs in #4408
  • fix(muya): consume autoCheck + hideLinkPopup options (PG3/PG12) by @Jocs in #4409
  • feat(muya): expose block affiliation in selection-change (PG1) by @Jocs in #4410
  • feat(muya): restore clipboard image paste + imageAction routing + copyAsRich (PG5/PG6/PG9) by @Jocs in #4411
  • fix(muya): inline export CSS + heading ids for offline export & TOC anchors (PG7/PG8) by @Jocs in #4412
  • feat(muya): emit preview-image + heading-copy-link events (PG10/PG11) by @Jocs in #4414
  • feat(muya): restore drag-and-drop image insertion (PG4) by @Jocs in #4413
  • feat(desktop): wire @muyajs/core parity APIs (menu state, copyAsRich, heading-link, source cursor, saved indicator) by @Jocs in #4415
  • fix(desktop): pass imageAction + getPathForFile to Muya constructor (re-activate PG4/5/6) by @Jocs in #4417
  • fix(muya): resolve pre-existing lint:css no-descending-specificity by @Jocs in #4419
  • fix(muya): record source-mode bulk edit as a single undo boundary (PG14) by @Jocs in #4420
  • test(desktop): remove redundant muyajs-engine unit specs (Phase F) by @Jocs in #4422
  • fix(desktop): retarget theme.ts editor CSS at muya mu-* classes (E4) by @Jocs in #4421
  • fix(desktop): port print image-src resolution off muyajs (last muya/lib import) by @Jocs in #4423
  • fix(muya): crash typing '#' β€” guard I18n.t + add heading-copy-link locale key by @Jocs in #4424
  • fix(muya): add missing image i18n keys ('Click to add an image' / 'Load image failed') by @Jocs in #4427
  • fix(muya): render relative image paths anchored to the document dir (Phase G blocker) by @Jocs in #4428
  • fix(desktop): Editβ–ΈReplace action + saved-indicator false-clean (Phase G) by @Jocs in #4431
  • fix(muya): preserve drive/UNC roots in relative image path resolution (#4428 review follow-up) by @Jocs in #4430
  • fix: source-mode cursor sync + language-switch hint refresh (Phase G G7/G8) by @Jocs in #4432
  • fix(muya): updateParagraph data-loss on list/quote + front-matter insertion + frontmatterType lang (Phase G) by @Jocs in #4429
  • test: cover @muyajs/core migration regression gaps (Phase G) by @Jocs in #4434
  • fix(muya): restore cross-cell table selection + resolve dead TableChessboard picker (Phase G) by @Jocs in #4435
  • test(muya): de-flake heading-locale + backspace regression specs (#4434 review) by @Jocs in #4436
  • fix(muya): restore the in-editor table grid picker (revert #4435 chessboard deletion + wire trigger) by @Jocs in #4437
  • docs: archive the muyajs β†’ @muyajs/core migration tracker by @Jocs in #4438
  • chore: keep .claude/ fully ignored (untrack migration tracker) by @Jocs in #4439
  • fix: restore editor visual parity after @muyajs/core migration by @Jocs in #4443
  • fix(muya): align Cmd+A / copy / cut / paste with legacy muyajs by @Jocs in #4446
  • chore(muya): align packages/muya conventions with desktop + doc cleanup by @Jocs in #4450
  • fix(muya): editor parity with muyajs (themes, fonts, spellcheck) + CLASS_NAMES cleanup by @Jocs in #4454
  • refactor(muya): split clipboard into modules + type copy/paste modes as enums by @Jocs in #4459
  • fix(muya): enable inline image resize by @Jocs in #4460
  • refactor(muya): rebuild ImageEditTool to match muyajs ImageSelector by @Jocs in #4461
  • chore: remove ununsed comments by @Jocs in #4462
  • chore(muya): remove redundant comments added during the muyajs port by @Jocs in #4463
  • refactor(muya): unify Selection into facade over Text/Table/Image sub-selections by @Jocs in #4467
  • fix(muya): match muyajs nested list spacing and bullet markers by @Jocs in #4469
  • fix(editor): restore caret on source-mode undo and tab switch by @Jocs in #4470
  • fix(muya): preventDefault on forward-delete paragraph merge by @Jocs in #4471
  • fix(muya): restore Paste as Plain Text via async clipboard read by @Jocs in #4472
  • fix(muya): stop drag-selection from expanding to whole blocks by @Jocs in #4477
  • fix(muya): delete whole image on backspace (inline, raw html, reference) by @Jocs in #4478
  • fix(muya): stop Shift+Tab unindent from crashing on insertTab by @Jocs in #4479
  • fix(muya): stop arrow nav from crashing on null cursor coords by @Jocs in #4480
  • fix(muya): clear the / trigger when quick-inserting front matter by @Jocs in #4481
  • fix(desktop): make Promote Heading shortcut fire on macOS by @Jocs in #4482
  • fix(desktop): refresh muya locale on language switch (hint + quick-insert menu stay translated) by @Jocs in #4489
  • fix(desktop): anchor theme card h3 label to its heading by @Jocs in #4490
  • fix(muya): stop in-flight float positioning from re-revealing a hidden float by @Jocs in #4491
  • fix(desktop): return relative image path for local-path-string inserts by @Jocs in #4492
  • fix: insert web images dragged from a browser by @Jocs in #4494
  • fix(muya): support resizing images that share the same link by @Jocs in #4495
  • fix(muya): render vega-lite diagrams under the renderer CSP by @Jocs in #4496
  • fix(muya): refresh local images on "Reload images" (View β†’ Reload images) by @Jocs in #4498
  • fix: reflect the current block in the Paragraph menu (PG1) by @Jocs in #4500
  • fix(muya): keep selection after applying an inline format to a range by @Jocs in #4501
  • fix(desktop): reflect underline/superscript/subscript/highlight in the Format menu by @Jocs in #4503
  • fix: paragraph menu / command palette parity (focus, list unwrap, shortcut symbols) by @Jocs in #4504
  • fix(muya): keep cursor in place when toggling Loose List Item by @Jocs in #4506
  • refactor(muya): rework the selection type surface by @Jocs in #4512
  • fix(desktop): point in-app docs links at marktext.me by @Jocs in #4513
  • fix(website): point self-referential doc links at the published docs by @Jocs in #4514
  • fix(website): register the missing end-user docs pages by @Jocs in #4515
  • feat(i18n): add Turkish (tr) locale by @FurkaanBoraa in #4510
  • feat: make PlantUML server URL configurable by @jyte in #4400
  • fix: #4474 unsaved indicator never clears after undoing back to on-disk content by @FurkaanBoraa in #4475
  • fix(test): correct PlantUML custom-server URL assertion by @Jocs in #4517
  • fix(i18n): reconcile desktop & muya locale keys after the muya engine refactor by @Jocs in #4516
  • test(muya): backfill engine-unit coverage for audited gaps by @Jocs in #4508
  • test(muya-e2e): backfill real-DOM e2e coverage for audited gaps by @Jocs in #4511
  • test(desktop): backfill renderer/main unit coverage for audited gaps by @Jocs in #4509
  • refactor(muya): return enums from TextSelection direction/type by @Jocs in #4519
  • refactor(muya): setSelection takes anchor/focus endpoints by @Jocs in #4523
  • refactor(muya): route format/codeblock selection through setCursor by @Jocs in #4520
  • refactor(muya): split ICursor into focused interfaces by @Jocs in #4524
  • refactor(muya): keep table rect selection exclusive of text selection by @Jocs in #4522
  • refactor(muya): extract computeDirection/computeCaretType helpers by @Jocs in #4525
  • refactor(muya): simplify selectAll into three escalation rules by @Jocs in #4526
  • test(muya): replace any with precise block/state types in specs by @Jocs in #4528
  • refactor(desktop): remove no-explicit-any suppressions in favor of precise types by @Jocs in #4527
  • refactor(muya): drop cyclomatic complexity below 20 across the engine by @Jocs in #4529
  • refactor(muya): rename selection enum members to UPPER_SNAKE_CASE by @Jocs in #4531
  • chore: translate remaining Chinese console/debug strings to English by @Jocs in #4533
  • refactor(muya): enforce _ prefix for private members via lint by @Jocs in #4535
  • refactor(muya): mark core/state/selection internals private by @Jocs in #4541
  • refactor(muya): mark block-tree internals private/protected by @Jocs in #4538
  • refactor(muya): mark UI float-tool internals private by @Jocs in #4539
  • refactor(desktop): remove remaining no-explicit-any suppressions by @Jocs in #4548
  • feat: align Paragraph/Format menus with muyajs behavior on @muyajs/core (+3 upgrades) by @Jocs in #4547
  • fix(muya): sync inline format toolbar highlight via selection-change by @Jocs in #4558
  • fix(muya): align normalizePastedHTML link unlinking with muyajs by @Jocs in #4550
  • fix(muya): render footnotes in copy-as-html / copy-as-rich clipboard HTML by @Jocs in #4544
  • fix(muya): align clipboard cut/delete semantics with muyajs by @Jocs in #4540
  • fix(muya): collapse code block to paragraph on cross-block cut from its language line (#918) by @Jocs in #4545
  • fix(muya): merge pasted paragraphs/headings inline (muyajs parity) by @Jocs in #4542
  • fix(muya): replace selected image on paste + language-input paste parity by @Jocs in #4543
  • fix(muya): merge same-type list paste + plain-text block HTML (muyajs parity) by @Jocs in #4546
  • fix(muya): round-2 paste/clipboard parity fixes from a full muyajs re-audit by @Jocs in #4549
  • fix: populate the table of contents on open and fix link navigation by @NSO73 in #4448
  • fix(desktop): paste captured image on macOS Edit β†’ Screenshot by @Jocs in #4566
  • fix(muya): restore editor cursor when closing the search bar (selectHighlight) by @Jocs in #4567
  • fix(muya): restore find-bar prefill from editor selection by @Jocs in #4569
  • fix(search): scroll editor to match when opening a folder-search result by @Jocs in #4568
  • fix(muya): serialize lists with the configured listIndentation by @Jocs in #4570
  • fix(muya): restore the focused frontmatter delimiter markers by @Jocs in #4571
  • fix(muya): show code-block line numbers on first render for language-less blocks by @Jocs in #4572
  • fix(muya): re-parse on parse-affecting option changes so ```math toggles live by @Jocs in #4573
  • fix(export): repair five styled-HTML export regressions (math, vega, footnotes, TOC, images) by @Jocs in #4576
  • fix(export): make "Overwrite theme font" actually override the selected theme by @Jocs in #4579
  • fix(editor): restore per-tab caret on tab switch by @Jocs in #4580
  • fix(editor): restore undo after an external file reload by @Jocs in #4582
  • fix(desktop): auto-focus the editor when creating or opening a tab by @Jocs in #4581
  • fix(editor): align code block line numbers vertically by @Jocs in #4583
  • fix(editor): keep spelling suggestions when "no underline" is enabled by @Jocs in #4584
  • refactor(muya): decouple engine/block layers from src/ui plugin internals by @Jocs in #4587
  • fix(clipboard): copy only the selected part of cross-block selections by @Jocs in #4586
  • fix(muya): correct setext heading level when typing the underline by @Jocs in #4591
  • fix(muya): guard checkNeedRender against a null cursor (image-preview reclick crash) by @Jocs in #4588
  • test(desktop): backfill renderer/main unit coverage for post-migration gaps by @Jocs in #4592
  • test(muya-e2e): backfill real-DOM e2e coverage for post-migration gaps by @Jocs in #4593
  • test(muya): backfill engine unit coverage for post-migration gaps by @Jocs in #4589
  • test(desktop): backfill app e2e coverage for post-migration gaps by @Jocs in #4594
  • chore(security): remediate 25 Dependabot alerts by @Jocs in #4596
  • chore(deps): upgrade all packages to latest + align shared versions by @Jocs in #4597
  • test(muya): poll for the html_tag mount instead of waiting a single frame by @Jocs in #4607
  • fix(muya): escape pipes at cell start and consecutive pipes in table serialization by @Jocs in #4601
  • fix(muya): absorb a manually typed closing markdown marker after text by @Jocs in #4602
  • fix(muya): let Shift+ArrowUp/Down extend selection while the inline toolbar is shown by @Jocs in #4603
  • fix(muya): render
  • fix(muya): keep emphasis intact when a line contains escaped dollar signs by @Jocs in #4605
  • fix(muya): paste a URL into link parentheses without nesting a markdown link by @Jocs in #4608
  • fix(muya): make links inside a raw HTML block clickable by @Jocs in #4609
  • fix(muya): correct inline code/math shortcut labels in the format toolbar by @Jocs in #4611
  • fix: #4356 crash when using the link popover on a link with an unsupported protocol by @FurkaanBoraa in #4473
  • fix(muya): map Β  to U+00A0 and keep escaped spaces unbreakable by @Jocs in #4612
  • fix(desktop): scroll to non-heading in-document anchors on Ctrl/Cmd-click by @Jocs in #4613
  • fix(muya): keep the inline-math parse-error message on one line by @Jocs in #4614
  • fix(muya): allow inline style in the html-block live preview by @Jocs in #4618
  • fix(muya): cap and horizontally scroll the inline-math popup by @Jocs in #4615
  • fix(desktop): isolate the editor stacking context so previews stay under modals by @Jocs in #4617
  • test(desktop): fix inline code/math shortcut tests failing on develop after #4611 by @FurkaanBoraa in #4624
  • fix(desktop): scroll CodeMirror to the heading on TOC click in source mode by @Jocs in #4619
  • fix(muya): constrain a rendered diagram svg so wide diagrams don't clip by @Jocs in #4616
  • fix(desktop): apply custom keybinding changes without an app restart by @Jocs in #4621
  • fix(muya): break undo entries at word and edit-kind boundaries by @Jocs in #4622
  • fix(muya): swap cross-block arrow boundary keys in RTL mode by @Jocs in #4610
  • fix: opaque light-theme editor text colors for crisp antialiasing by @Jocs in #4631
  • fix(muya): clamp selection offset to the node's legal range by @Jocs in #4626
  • fix(desktop): prevent data loss when closing after Source Code mode edits by @Jocs in #4627
  • fix(muya): center inline math vertically so it sits on the text baseline by @Jocs in #4632
  • fix(muya): render inline math containing an escaped dollar sign by @Jocs in #4629
  • fix(muya): prevent renderer crash when deleting consecutive thematic breaks by @Jocs in #4628
  • test: drop the low-value opaque-color guard tests from #4466 by @Jocs in #4633
  • test(muya): regression guard for code-block scroll on typing (#3191) by @Jocs in #4638
  • fix(muya): align serialized table columns by visual width (#1983) by @Jocs in #4636
  • fix(muya): insert ordinary spaces for Tab instead of non-breaking spaces (#3273) by @Jocs in #4634
  • fix(muya): convert typed diagram fences to diagram blocks on Enter (#2177) by @Jocs in #4635
  • fix(muya): keep the caret on Shift+Tab list unindent (REPLACEMENT path) (#3223) by @Jocs in #4637
  • fix(muya): typed diagram fences create diagram blocks via the language selector (#2177) by @Jocs in #4640
  • refactor: rewrite getTOC and remove unused comments by @Jocs in #4642
  • fix(muya): allow trailing whitespace after a math block's closing $$ (#1931) by @Jocs in #4649
  • fix(muya): stop ArrowDown from endlessly creating empty paragraphs (#3520) by @Jocs in #4650
  • fix(muya): take the list marker from a line start in _convertToList (#2429) by @Jocs in #4651
  • fix(muya): strip trailing punctuation from extended autolinks (#2096) by @Jocs in #4652
  • fix(muya): ArrowUp at document start moves the caret to offset 0 (#3193) by @Jocs in #4655
  • fix(muya): destroy UI plugins on Muya.destroy() to stop leaking DOM nodes (#3315) by @Jocs in #4659
  • fix(muya): don't cut a cross-block selection on Ctrl+ (Windows/Linux) (#3491) by @Jocs in #4656
  • fix(muya): apply inline format across paragraphs nested in one blockquote (#3462) by @Jocs in #4661
  • fix: #4534 group theme menu into Light/Dark submenus by @FurkaanBoraa in #4623
  • fix(muya): drop pending op batch on setContent to prevent cross-document corruption (#2938) by @Jocs in #4658
  • test(desktop): pin autosave's recreate-missing-directory behavior (#3509) by @Jocs in #4657
  • fix(muya): keep list item non-empty on Enter in empty first paragraph (#4644) by @Jocs in #4660

New Contributors

Full Changelog: v0.19.0...v0.20.0-beta.2

  •  

v0.19.1

6 Juni 2026 om 07:05

⚠️ Note for macOS users

Builds are unsigned (no Apple Developer ID). After dragging MarkText into Applications, clear the quarantine flag once:

xattr -cr /Applications/marktext.app

Verifying downloads

All artifacts are listed with their SHA-256 in SHA256SUMS.txt. Verify with:

sha256sum -c SHA256SUMS.txt --ignore-missing

What's Changed

  • chore(release): v0.19.0 release branch (DO NOT MERGE until stable) by @Jocs in #4269
  • chore: bump develop to 0.20.0-dev by @Jocs in #4296
  • docs(release): update Step 7 asset list to 24 by @Jocs in #4298
  • docs(end-user): align user docs with 0.19 prefs and platform matrix by @Jocs in #4300
  • docs(dev): sync developer docs with current codebase by @Jocs in #4299
  • chore: convert repo to pnpm monorepo (packages/desktop, muyajs, website) by @Jocs in #4302
  • refactor(website): migrate to Next.js 15 + Cloudflare Workers CI by @Jocs in #4305
  • feat(website): serve www.marktext.me (301 β†’ apex) by @Jocs in #4308
  • fix(website): wwwβ†’apex redirect (middleware) + smarter preview-URL parsing by @Jocs in #4309
  • ci(website): enable Preview URLs on marktext-website Worker by @Jocs in #4311
  • refactor(website): redesign landing page, drop markdown engine deps by @Jocs in #4312
  • feat(muya): migrate TS rewrite to packages/muya alongside legacy muyajs by @Jocs in #4314
  • feat(website): add /docs route and consolidate docs/ under packages/website/ by @Jocs in #4316
  • fix: replace remaining absolute raw.githubusercontent.com URLs with relative paths in READMEs by @Copilot in #4329
  • fix(website): serve prerendered docs pages via static-assets cache by @Jocs in #4335
  • fix(website): open download buttons in new tab pointing to releases page by @Jocs in #4336
  • refactor(website): simplify docs subtree (palette / sidebar / markdown / nav) by @Jocs in #4349
  • refactor(website): simplify landing page (helpers, types, data-driven blocks) by @Jocs in #4350
  • chore(website): tighten middleware matcher; drop unused 'use client' by @Jocs in #4351
  • fix(muyajs): preserve nested lists of differing types (#4341) by @Jocs in #4354
  • fix(muyajs): allow CJK ideographs as flanking boundary for emphasis by @Jocs in #4355
  • fix(muyajs): clamp setStart offset to legal range to prevent IndexSizeError (#2800) by @Jocs in #4358
  • fix(muyajs): null-guard list block paths to prevent renderer crash (#4346) by @Jocs in #4359
  • fix: restore local builds after monorepo split by @Jocs in #4361

New Contributors

  • @Copilot made their first contribution in #4329

Full Changelog: v0.19.0...v0.19.1

  •  

v0.19.0

28 Mei 2026 om 16:03

⚠️ Note for macOS users

Builds are unsigned (no Apple Developer ID). After dragging MarkText into Applications, clear the quarantine flag once:

xattr -cr /Applications/marktext.app

Verifying downloads

All artifacts are listed with their SHA-256 in SHA256SUMS.txt. Verify with:

sha256sum -c SHA256SUMS.txt --ignore-missing

What's Changed

  • Ignore empty key bindings by @fxha in #3077
  • Update auto pair quote logic by @Lorilandly in #2960
  • Fix image paste handler is not executed by @fxha in #3076
  • Add experimental native support for Apple M1 by @fxha in #3089
  • Update dependencies by @fxha in #3096
  • Fix: "delete" shortcut on a selected image deletes the text after it (#2816) by @kiyoka in #3088
  • Fix links to macOS releases by @yous in #3099
  • Fix typo in the DataCenter class init method by @vdeschuy in #3104
  • 0.17.1 by @fxha in #3105
  • Fixed multi line highlight. by @or1ko in #3115
  • Don't copy (or on cut) empty data to the clipboard, matches native behavior by @mitchcapper in #3130
  • Upgrade Electron to v17 by @fxha in #3138
  • Remove Wayland workaround by @fxha in #3147
  • Refactor menu actions and shortcut handling by @fxha in #3032
  • Replace node-spellchecker with Electron builtin spell checker by @fxha in #2895
  • Remove expired "marktext.app" domain by @CouldBeThis in #3350
  • fix wrong logo path in ko.md by @heli-os in #3576
  • Update Traditional Chinese translation of README by @ChiahongHong in #3264
  • Update dependencies by @fxha in #3213
  • Add .mdx extension support by @davidknezic in #3438
  • FIX: 'yarn run test:specs' command fails to load @markedjs/html-differ (#3330) by @kiyoka in #3331
  • fix #3150: Win32 error in renderer process by @fxha in #3214
  • Fix roadmap link by @fulldecent in #3678
  • upgrade to mermaid 10 by @ivy-rew in #3734
  • [i18n] Improve portuguese translation on the README by @tiagozip in #3813
  • chore: update readme add Inkio and remove broken link by @Jocs in #4084
  • chore: Update outdated GitHub Actions versions by @pgoslatara in #4113
  • Add arabic lang for doc by @Almohawis in #4097
  • chore: update readme file by @Jocs in #4136
  • docs: improve grammar & punctuation by @RightWrite in #3939
  • add .claude .agents to gitignore by @chongchonghe in #4172
  • Note added according to the issue #2208 by @aespondac in #3867
  • fix: upload failure with github (#3588) by @left0ver in #3589
  • Fix not colored emojis on popup by @fxha in #3215
  • fix issue 3268 by @hahaha28 in #3269
  • fix: #4153 suppress EPIPE crash in main process by @Wordbe in #4154
  • New feature: Opening image file with the external tool (#2321) by @kiyoka in #3007
  • fix: guard null imageContainer.firstChild in getImageInfo by @Jocs in #4193
  • fix: prevent querySelector crash on empty heading slug by @Bowl42 in #4135
  • Re-Factor MarkText with electron-vite by @Tkaixiang in #4001
  • fix: restore docs accidentally deleted in PR #4001 (electron-vite refactor) by @Jocs in #4196
  • restore: recover accidentally deleted tests from PR #4001 by @Jocs in #4197
  • chore: upgrade project dependencies to latest compatible versions by @Jocs in #4199
  • translate: convert all Chinese code comments to English by @Jocs in #4201
  • fix: fix ESLint configuration and resolve all lint errors by @Jocs in #4202
  • fix: resolve post-refactor regressions from electron-vite migration by @Jocs in #4203
  • Make native menu theme follow app theme by @johnsmith507 in #4205
  • feat: add GitHub Sponsors button to repository by @Jocs in #4207
  • feat: update sponsor by @Jocs in #4208
  • i18n: translate sponsor section in all language READMEs by @Jocs in #4209
  • fix: support Node v24+ with native-keymap C++20 patch and automated postinstall by @Jocs in #4211
  • fix: ensure npm run dev works after npm install on Node v24+ by @Jocs in #4212
  • feat: migrate package manager from npm to pnpm by @Jocs in #4213
  • docs: display special sponsor as a Markdown table by @Jocs in #4215
  • docs: update stale references and add CLAUDE.md by @Jocs in #4216
  • ci: replace manual test_pr with automated PR workflows by @Jocs in #4218
  • fix: word count tooltip not showing on macOS by @Jocs in #4219
  • fix: restore image fullscreen viewer broken by view-image removal by @Jocs in #4221
  • feat: restore third-party license tooling and add CI validation by @Jocs in #4220
  • fix: prevent crash in normalizeTable when body row has more cells than header by @Jocs in #4222
  • fix: skip conflict detection for unbound shortcuts in keybinding loader by @Jocs in #4223
  • fix: avoid reloading existing i18n locales by @cerredz in #4224
  • fix: migrate jsconfig.json away from deprecated baseUrl (TS 6.0) by @Jocs in #4225
  • fix: remove unused languine dependency (resolves CVE-2026-41650) by @Jocs in #4226
  • chore: remove unused deps and upgrade all dependencies to latest by @Jocs in #4227
  • ci: add Claude Code Action workflow by @Jocs in #4228
  • fix: add pnpm-workspace.yaml to approve build scripts for native deps by @Jocs in #4230
  • fix: build error when build mac target by @Jocs in #4232
  • fix: use default font smoothing by @cerredz in #4217
  • docs: update CommonMark Spec links to latest version by @Jocs in #4235
  • fix: #4151 preserve scroll position on external file change by @Wordbe in #4152
  • fix: Internal image cache isn't reset if failed to load (#3001) by @kiyoka in #3010
  • Allow scrolling down even if no contents below by @szdytom in #3405
  • Added Arch Linux to development dependencies in BUILD.md by @lawgimenez in #3381
  • fix(i18n): capitalize GitHub in English and Portuguese locale strings by @Blueteemo in #4238
  • docs: expand CLAUDE.md with single-test recipes and dev script catalog by @Jocs in #4239
  • fix: unblock local lint and vitest runs by @Jocs in #4240
  • test(e2e): broaden Playwright coverage with menu/IPC-driven specs by @Jocs in #4241
  • fix(ui): repair Insert Table dialog wrap and overhaul Help menu by @Jocs in #4242
  • fix(source-view): stop styling math subscripts as emphasis (#4121) by @Jocs in #4243
  • feat(security): sandbox the renderer (contextIsolation, nodeIntegration: false, sandbox: true) by @Jocs in #4244
  • feat(ts): migrate the entire project to TypeScript by @Jocs in #4247
  • refactor(stores): type editor + preferences Pinia stores (TS migration follow-up 1/6) by @Jocs in #4249
  • refactor(renderer): type prefComponents schemas + leaf SFC controls (TS migration follow-up 2/6) by @Jocs in #4250
  • refactor(test): port specs to strict TS β€” drop @ts-nocheck, ESM imports (TS migration follow-up 3/6) by @Jocs in #4251
  • refactor(renderer): type sidebar + top-level SFCs β€” drop @ts-nocheck (TS migration follow-up 4/6) by @Jocs in #4252
  • refactor(renderer): type editor + components SFCs β€” drop @ts-nocheck (TS migration follow-up 5/6) by @Jocs in #4253
  • refactor(renderer): type preference page SFCs β€” drop @ts-nocheck (TS migration follow-up 6/6) by @Jocs in #4254
  • chore(eslint): tighten @typescript-eslint/no-explicit-any to error (TS migration follow-up 7/7) by @Jocs in #4255
  • chore(eslint): ignore .claude/ worktree clones in lint runs by @Jocs in #4256
  • fix(ipc): tighten three IPC channels + SET_IMAGE_FOLDER_PATH signature by @Jocs in #4258
  • fix(renderer): editor fills width when sidebar collapses to icon strip by @Jocs in #4262
  • style(preferences): polish dialog UI and unify design by @Jocs in #4263
  • style(ui): batch polish sidebar, tabs, preferences, and theme contrast by @Jocs in #4264
  • style(sidebar): unify collapse arrows and tighten tree spacing by @Jocs in #4265
  • fix(muya): guard stale cursor/block lookups against null by @Jocs in #4267
  • ci(release): split into validateβ†’buildβ†’publish, harden workflow by @Jocs in #4266
  • test(e2e): regression guards for previously-reported "Unexpected error" crashes by @Jocs in #4268
  • docs(release): expand RELEASE.md into a step-by-step playbook by @Jocs in #4270
  • fix(release): restore updater metadata artifacts by @Jocs in #4272
  • fix(sidebar): create-file button works in non-English locales by @Jocs in #4273
  • chore: remove unused SVG icons from renderer by @Jocs in #4275
  • FIx: switch path-browserify to Pathe + image pasting on windows + cleanup console.logs by @Tkaixiang in #4274
  • refactor(image): remove GitHub uploader and None option; default to PicGo by @Jocs in #4276
  • feat(sidebar): implement file & folder sort with natural ordering by @Jocs in #4277
  • feat(sidebar): add toggle to hide Opened Files + cap list to 4 items by @Jocs in #4278
  • build: add Windows ARM64 native build support by @Jocs in #4279
  • fix(uploader): remove 5 MB hard limit on image uploads by @Jocs in #4280
  • fix(preferences): update broken doc links to correct develop-branch paths by @Jocs in #4281
  • fix(build): restore dedicated .md file icon on Windows by @Blueteemo in #4284
  • chore: remove residual Unsplash code by @Jocs in #4286
  • chore: remove dead code and debug noise by @Jocs in #4287
  • refactor(editor): rename LINTEN_FOR_* typos and unify JSON deep-clones by @Jocs in #4288
  • perf(filesystem): cut stat syscalls and per-call regex compilation by @Jocs in #4289
  • chore: misc simplifications by @Jocs in #4290

New Contributors

Full Changelog: v0.17.0...v0.19.0

  •  

v0.19.0-rc.4

27 Mei 2026 om 05:59

❗ This is a pre-release

  • May contain bugs and unfinished features.

⚠️ Note for macOS users

Builds are unsigned (no Apple Developer ID). After dragging MarkText into Applications, clear the quarantine flag once:

xattr -cr /Applications/marktext.app

Verifying downloads

All artifacts are listed with their SHA-256 in SHA256SUMS.txt. Verify with:

sha256sum -c SHA256SUMS.txt --ignore-missing

What's Changed

  • fix(preferences): update broken doc links to correct develop-branch paths by @Jocs in #4281
  • fix(build): restore dedicated .md file icon on Windows by @Blueteemo in #4284

Full Changelog: v0.19.0-rc.3...v0.19.0-rc.4

  •  

v0.19.0-rc.3

25 Mei 2026 om 05:03

❗ This is a pre-release

  • May contain bugs and unfinished features.

⚠️ Note for macOS users

Builds are unsigned (no Apple Developer ID). After dragging MarkText into Applications, clear the quarantine flag once:

xattr -cr /Applications/marktext.app

Verifying downloads

All artifacts are listed with their SHA-256 in SHA256SUMS.txt. Verify with:

sha256sum -c SHA256SUMS.txt --ignore-missing

What's Changed

  • docs(release): expand RELEASE.md into a step-by-step playbook by @Jocs in #4270
  • fix(release): restore updater metadata artifacts by @Jocs in #4272
  • fix(sidebar): create-file button works in non-English locales by @Jocs in #4273
  • chore: remove unused SVG icons from renderer by @Jocs in #4275
  • FIx: switch path-browserify to Pathe + image pasting on windows + cleanup console.logs by @Tkaixiang in #4274
  • refactor(image): remove GitHub uploader and None option; default to PicGo by @Jocs in #4276
  • feat(sidebar): implement file & folder sort with natural ordering by @Jocs in #4277
  • feat(sidebar): add toggle to hide Opened Files + cap list to 4 items by @Jocs in #4278
  • build: add Windows ARM64 native build support by @Jocs in #4279
  • fix(uploader): remove 5 MB hard limit on image uploads by @Jocs in #4280

Full Changelog: v0.19.0-rc.2...v0.19.0-rc.3

  •  

v0.19.0-rc.2

24 Mei 2026 om 09:05

❗ This is a pre-release

  • May contain bugs and unfinished features.

⚠️ Note for macOS users

Builds are unsigned (no Apple Developer ID). After dragging MarkText into Applications, clear the quarantine flag once:

xattr -cr /Applications/marktext.app

Verifying downloads

All artifacts are listed with their SHA-256 in SHA256SUMS.txt. Verify with:

sha256sum -c SHA256SUMS.txt --ignore-missing

Full Changelog: v0.19.0-rc.1...v0.19.0-rc.2

  •  

Firefox 155.0.1

4 September 2026 om 16:05

Fixed

  • Fixed Firefox becoming unresponsive on some pages that use CSS blur and backdrop filters together. (Bug 2068836)

  • Fixed the sidebar not reappearing after restarting Firefox when the "Hide tabs and sidebar" option was turned on. (Bug 2065431)

  • Fixed some profile icons not being displayed in the account and application menus. (Bug 2064729, Bug 2067734)

  • Fixed the current device being listed among connected devices in the account menu. (Bug 2059763)

Unresolved

  • Standard dynamic range (SDR) video in some formats can appear washed out on macOS. The issue is under investigation and a fix will ship in a future release. (Bug 2068961)

  •  

Early Stable Update for Desktop

3 September 2026 om 22:14

The Stable channel has been updated to 153.0.8010.27/.28 for Windows. Mac is coming shortly , as part of our early stable release to a small percentage of users. A full list of changes in this build is available in the log.

You can find more details about early Stable releases here.

Interested in switching release channels? Β Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.


Srinivas Sista

Google Chrome

  •  

Stable Channel Update for Desktop

3 September 2026 om 21:22

The Stable channel has been updated to 152.0.7977.82/.83 for Windows and Mac and 152.0.7977.82 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available in the LogΒ 


Security Fixes and Rewards

Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.


This update includes 12 security fixes. Please see the Chrome Security Page for more information.


[$1,000][542403045] High CVE-2026-85046: Type confusion in V8. Reported by Salvatore Gulizia (nickname: Serotav) on 2026-08-04

[N/A][502304489] High CVE-2026-85052: Out of bounds read in CrashReporting. Reported by Google on 2026-04-13
[N/A][533502257] High CVE-2026-85043: Incomplete cleanup in Network. Reported by Google on 2026-07-10
[TBD][540357382] High CVE-2026-85048: Use after free in Compositing. Reported by Ngoc Hieu on 2026-07-29
[TBD][547819997] High CVE-2026-85045: Race condition in V8. Reported by Brendan Dolan-Gavitt, XBOW on 2026-08-17
[N/A][549350408] High CVE-2026-85050: Out of bounds write in WebGL. Reported by Google on 2026-08-20
[TBD][552689418] High CVE-2026-85053: Improper resource exposure in CacheStorage. Reported by Salvatore Gulizia (Serotav) on 2026-08-26
[N/A][553119925] High CVE-2026-85042: Use after free in DevTools. Reported by Google on 2026-08-26
[N/A][553345874] High CVE-2026-85049: Use after free in Skia. Reported by Google on 2026-08-27
[N/A][553449113] High CVE-2026-85051: Type confusion in Compositing. Reported by Google on 2026-08-27
[N/A][513790581] Medium CVE-2026-85047: Improper input validation in Transactions Platform. Reported by Google on 2026-05-16
[N/A][517482830] Medium CVE-2026-85044: Use of released resource in Mobile. Reported by Google on 2026-05-28

Google is aware that an exploit for CVE-2026-85046 exists in the wild.

We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.


Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.

Srinivas Sista
Google Chrome
  •  

Stable Channel Update for Desktop

2 September 2026 om 00:23

The Stable channel has been updated to 152.0.7977.75/.76 for Windows and Mac and 152.0.7977.75 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available in the LogΒ 

Security Fixes and Rewards

Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.


This update includes 26 security fixes. Please see the Chrome Security Page for more information.


[N/A][522307103] Critical CVE-2026-84353: Use after free in Shared Tab Groups. Reported by Google on 2026-06-10

[N/A][546260492] Critical CVE-2026-84352: Use after free in WebGL. Reported by Google on 2026-08-14

[N/A][498839176] High CVE-2026-84354: Incorrect authorization in FileSystem. Reported by Google on 2026-04-02

[N/A][514078656] High CVE-2026-84359: Information leak in Skia. Reported by Google on 2026-05-17

[N/A][523208474] High CVE-2026-84357: Improper input validation in Omnibox. Reported by Google on 2026-06-12

[N/A][533534913] High CVE-2026-84324: Use after free in Proxy. Reported by Google on 2026-07-10

[N/A][537105664] High CVE-2026-84349: Use after free in Browser. Reported by Google on 2026-07-21

[TBD][547936520] High CVE-2026-84326: Uninitialized resource in V8. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern) on 2026-08-17

[N/A][549311485] High CVE-2026-84333: Use after free in Dawn. Reported by Google on 2026-08-19

[TBD][551593376] High CVE-2026-84351: Buffer overflow in GPU. Reported by Cassio Lima on 2026-08-24

[N/A][553117928] High CVE-2026-84325: Improper input validation in DataTransfer. Reported by Google on 2026-08-26

[N/A][498710886] Medium CVE-2026-84328: Missing authorization in FileSystem. Reported by Google on 2026-04-01

[N/A][501679156] Medium CVE-2026-84347: Use after free in WebRTC. Reported by Google on 2026-04-11

[N/A][502411391] Medium CVE-2026-84323: Missing authorization in FileSystem. Reported by Google on 2026-04-14

[N/A][511774376] Medium CVE-2026-84355: Incorrect authorization in Navigation. Reported by Google on 2026-05-10

[N/A][514006886] Medium CVE-2026-84358: Improper privilege management in Downloads. Reported by Google on 2026-05-17

[N/A][514489238] Medium CVE-2026-84332: Incorrect authorization in SiteSettings. Reported by Google on 2026-05-19

[N/A][517091927] Medium CVE-2026-84330: UI misrepresentation in FullScreen. Reported by Google on 2026-05-27

[N/A][517798926] Medium CVE-2026-84334: Incorrect authorization in Chromoting. Reported by Google on 2026-05-29

[N/A][518100026] Medium CVE-2026-84348: Information leak in MediaCapture. Reported by Google on 2026-05-30

[N/A][522302504] Medium CVE-2026-84335: Incorrect authorization in TabStrip. Reported by Google on 2026-06-10

[N/A][498725213] Low CVE-2026-84327: Incorrect authorization in Autofill. Reported by Google on 2026-04-01

[N/A][498850269] Low CVE-2026-84329: Confused deputy in CredentialProvider. Reported by Google on 2026-04-02

[TBD][503787232] Low CVE-2026-84356: UI misrepresentation in FullScreen. Reported by Francesco Topol (k4tedu) on 2026-04-18

[N/A][513713427] Low CVE-2026-84350: Use after free in TabStrip. Reported by Google on 2026-05-16

[N/A][521753402] Low CVE-2026-84331: Incorrect authorization in Actor. Reported by Google on 2026-06-09


We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.


Many of our security bugs are detected using AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, or AFL.


Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.


Srinivas Sista

Google Chrome

  •  

Firefox 155.0

1 September 2026 om 19:15

New

  • Smart Window is now available for all users in the USA, Canada, and France to try out! Additionally, Firefox 155 includes many new enhancements:

    • New personalized resume conversation starters help users quickly return to topics they’ve been working on.

    Screenshot of Smart Window resume conversation helpers

    • Assistant now responds much faster with Exa web search source citations to provide accurate, trustworthy web grounding in roughly 1/5 the time.

    Screenshot of Smart Window Exa citations

    • Organize Tabs now suggests better groupings of your related tabs and gives each group a clearer, more descriptive name.

    Screenshot of Smart Window tab grouping

  • Firefox now shows how many trackers it has blocked in the address bar, making built-in privacy protections easier to see while browsing. The count can be hidden in settings without turning off tracker blocking.

  • Nintendo Switch Pro and compatible aftermarket controllers now work fully in web games on Windows, with the directional pad and analog sticks correctly mapped.

  • Containers can now be reordered in Settings, and the new order is used wherever containers are listed.

    Screenshot showing a container being dragged for reordering in the settings

  • The Translations feature now supports the following languages:

    • Marathi
    • Urdu

Fixed

  • Fixed text disappearing in Microsoft 365 Word Online and other web apps on Linux when typing with certain keyboard layouts.

  • Fixed an unnecessary paste confirmation appearing when using the keyboard shortcut to paste without formatting in Google Docs.

  • Firefox now recovers from the toolbar and tab strip being left unresponsive when the platform fails to end a tab drag session.

  • Fixed text inside buttons not being selectable or copyable, which prevented copying direct messages on X and comments on YouTube.

  • Fixed live audio streams such as internet radio stopping when playing in the background.

  • Fixed the sound indicator disappearing from a tab that was moved to another window, leaving no way to see or mute what was playing.

  • Fixed Firefox preventing Linux systems from going to sleep after a long browsing session.

  • Fixed full screen content being letterboxed on MacBooks with a camera notch, most visibly when watching video.

  • Fixed arrow-key and Page Up/Down scrolling not working on some pages with embedded content from other sites.

  • Fixed characters from some less common scripts appearing as empty boxes on web pages on Windows.

  • Fixed WebCodecs VideoEncoder hanging on macOS when encoding a VideoFrame in NV12 format.

  • Various security fixes.

Changed

  • Firefox now limits CSS to 75 levels of nested blocks and functions, preventing crashes that extremely deep nesting can cause under some circumstances. More deeply nested rules and values no longer parse.

  • Firefox now uses firefox-portal-detection.com instead of detectportal.firefox.com to detect captive portals and check network connectivity, so network allowlists referencing the old domain need updating.

  • Firefox now opens mailto: links only in response to an explicit user action, so pages can no longer launch the default mail client unprompted.

  • PDFs smaller than the paper size can now be enlarged to fill the sheet when printing, by setting the scale above 100%.

Enterprise

Developer

  • Developer Information
  • The Rules View now offers toggles to emulate the prefers-reduced-motion media feature. Emulation options have also moved into a new panel behind the at-rules (@) button.

  • The Debugger in Developer Tools now has a keyboard shortcut, Ctrl+Alt+B (Cmd+Alt+B on macOS), to enable or disable all breakpoints at once.

  • The JSON Viewer now displays JSON Lines (JSONL/NDJSON) documents, including inline errors for invalid lines.

  • Fixed the Storage panel showing cookies from private windows, containers, and other partitions alongside the inspected page's own cookies.

  • Uncaught non-Error exceptions now list their property names in the Console instead of showing only Object.

Web Platform

  • The CSS attr() function now supports values of any type, so authors can use attribute values in any property rather than only as strings in the content property.

  • Firefox now supports the progress() CSS function.

  • Firefox now supports the alpha() CSS function. This is a relative color function that can be used to modify just the alpha component of a given color.

  • Firefox now supports the Promise.allKeyed and Promise.allSettledKeyed methods from the await dictionary proposal, which take an object of promises and resolve to an object of results with the same keys.

  • Firefox now supports the WebAssembly Compact Import Section proposal, which can reduce the size of WebAssembly modules with many imports.

  • Firefox now supports the WebAssembly Wide Arithmetic proposal, which adds 128-bit arithmetic instructions for better performance in cryptography and arbitrary-precision math.

  • Firefox now supports QUIC version 2 (RFC 9369) for HTTP/3 connections, and uses it when the server selects it through compatible version negotiation (RFC 9368).

  • Support for the non-standard ::-webkit-scrollbar pseudo-element, added in Firefox 153, is now limited to a small list of sites rather than applying universally.

  • SVG <a> elements now expose the same URL properties as HTML links, including protocol, host, pathname, and search.

  • SVGGraphicsElement.getBBox() now honors its options argument, so bounding boxes can include stroke, markers, and clipping.

  • The font-width property is now supported as the standard name for font-stretch.

  • A dynamic import() that fails due to a network or HTTP error is no longer cached as a failure in the module map, so retrying the same specifier can now succeed.

  • WebTransport now supports send groups (createSendGroup()) for controlling how bandwidth is shared between streams, writable datagram streams (createWritable()), and exportKeyingMaterial() for deriving keys bound to the TLS session. It also adds a draining promise and subprotocol negotiation through the constructor's protocols option and the protocol property.

  • Firefox now supports RTCError for data channel failures, RTCSctpTransport.maxChannels, two-byte RTP header extension IDs, and more accurate RTCTransportStats, improving WebRTC interoperability.

Unresolved

  • For users with vertical tabs enabled, the sidebar may not persist across Firefox restarts. Vertical tabs can be re-enabled after the restart by clicking the sidebar toolbar button. A fix is available in Firefox 155.0.1.

  • Some sites may load slowly or fail to load on networks that block UDP. This can affect e.g. corporate networks where a proxy or firewall blocks QUIC as part of TLS inspection. To work around it, set network.http.happy_eyeballs_enabled to false with the Preferences policy. A fix is available in Firefox 155.0.1. (Bug 2063452)

  • Standard dynamic range (SDR) video in some formats can appear washed out on macOS. The issue is under investigation and a fix will ship in a future release. (Bug 2068961)

Community Contributions

  •  

Dopamine 3.0.10

Door: digimezzo
28 Augustus 2026 om 18:53

[3.0.10] - 2026-08-28

Changed

  • Improved the equalizer design
  • Updated the German translation (Thank you @mgfirewater)
  • Updated the Russian translation (Thank you @adem4ik)

Fixed

  • Empty strings in Equalizer with incomplete language packs
  • When sorting large playlists, songs sometimes still move back to their original position.
  • Mini player has incorrect size on macOS
  • Window restore issues on macOS and GNU/Linux (Wayland)

  •  

Early Stable Update for Desktop

26 Augustus 2026 om 19:14

The Stable channel has been updated to 153.0.8010.12/.13 for Windows and Mac as part of our early stable release to a small percentage of users. A full list of changes in this build is available in the log.

You can find more details about early Stable releases here.

Interested in switching release channels? Β Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.


Srinivas Sista

Google Chrome

  •  

FileZilla Client 3.71.1 released

Door: Tim Kosse
26 Augustus 2026 om 16:11

Bugfixes and minor changes:

  • macOS: Work around a bug in macOS 27 where setting the locale to non-English triggers crashes in AppKit
  • SFTP: Improved heuristic when keyboard-interactive requests are treated as a simple password prompt on servers not offering the password authentication method
  •  

Stable Channel Update for Desktop

25 Augustus 2026 om 21:19

The Chrome team is delighted to announce the promotion of Chrome 152 to the stable channel for Windows, Mac and Linux. This will roll out over the coming days/weeks.

Chrome 152.0.7977.64 (Linux)Β 152.0.7977.64/.65Β Windows/Mac contains a number of fixes and improvements -- a list of changes is available in the log. Watch out for upcoming Chrome and Chromium blog posts about new features and big efforts delivered in 152.


Security Fixes and Rewards

Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.

This update includes 327 security fixes. Please see the Chrome Security Page for more information.


[$25,000][496807874] Critical CVE-2026-79282: Use after free in ANGLE. Reported by Goodluck on 2026-03-27

[N/A][516427761] Critical CVE-2026-79290: Use after free in Aura. Reported by Google on 2026-05-25

[N/A][516764384] Critical CVE-2026-79054: Use after free in Chromecast. Reported by Google on 2026-05-26

[N/A][516777082] Critical CVE-2026-79121: Improper input validation in Chromecast. Reported by Google on 2026-05-26

[N/A][516988476] Critical CVE-2026-79224: Use after free in Chromecast. Reported by Google on 2026-05-27

[N/A][517518019] Critical CVE-2026-79052: Use after free in Aura. Reported by Google on 2026-05-28

[N/A][518006007] Critical CVE-2026-79150: Use after free in Views. Reported by Google on 2026-05-29

[N/A][522082472] Critical CVE-2026-78935: Use of uninitialized variable in Mobile. Reported by Google on 2026-06-10

[N/A][523704817] Critical CVE-2026-79012: Use after free in Safebrowsing. Reported by Google on 2026-06-13

[N/A][532921800] Critical CVE-2026-79200: Use after free in Aura. Reported by Google on 2026-07-09

[$1,000][532617619] High CVE-2026-78989: Out of bounds read in ANGLE. Reported by Đặng Thế Tuyến on 2026-07-09

[$500][508638064] High CVE-2026-79069: Memory corruption in Tint. Reported by andryskowski.michal on 2026-05-01

[N/A][498885920] High CVE-2026-79175: Type confusion in Accessibility. Reported by Google on 2026-04-02

[N/A][500311587] High CVE-2026-79218: Incorrect authorization in Sandbox. Reported by Google on 2026-04-07

[N/A][501892500] High CVE-2026-79195: Use after free in Script. Reported by Google on 2026-04-12

[N/A][513261751] High CVE-2026-78939: Use after free in Chromecast. Reported by Google on 2026-05-14

[N/A][515470739] High CVE-2026-79194: Use after free in Chromoting. Reported by Google on 2026-05-21

[N/A][515473074] High CVE-2026-79247: Use after free in Chromoting. Reported by Google on 2026-05-21

[N/A][516947491] High CVE-2026-79219: Use after free in Bluetooth. Reported by Google on 2026-05-27

[N/A][517515945] High CVE-2026-79047: Use after free in Views. Reported by Google on 2026-05-28

[N/A][517519352] High CVE-2026-79292: Integer overflow in Chromecast. Reported by Google on 2026-05-28

[N/A][517527943] High CVE-2026-78986: Uninitialized resource in GPU. Reported by Google on 2026-05-28

[N/A][517548647] High CVE-2026-79039: Use after free in Mobile. Reported by Google on 2026-05-28

[N/A][517550232] High CVE-2026-78934: Race condition in ReadAloud. Reported by Google on 2026-05-28

[N/A][517736936] High CVE-2026-79011: UI misrepresentation in Browser. Reported by Google on 2026-05-29

[N/A][517742721] High CVE-2026-78911: Incorrect authorization in USB. Reported by Google on 2026-05-29

[N/A][517959443] High CVE-2026-79257: Use after free in Views. Reported by Google on 2026-05-29

[N/A][521285077] High CVE-2026-79202: Use after free in Chromecast. Reported by Google on 2026-06-08

[N/A][521502218] High CVE-2026-79212: Missing authorization in Passwords. Reported by Google on 2026-06-08

[N/A][521942358] High CVE-2026-79183: Use after free in Accessibility. Reported by Google on 2026-06-09

[N/A][522294538] High CVE-2026-79155: Race condition in FileSystem. Reported by Google on 2026-06-10

[N/A][523095011] High CVE-2026-79093: Incorrect authorization in Paint. Reported by Google on 2026-06-12

[N/A][523266585] High CVE-2026-79019: Out of bounds write in ANGLE. Reported by Google on 2026-06-12

[N/A][523296105] High CVE-2026-79187: Use after free in WebRTC. Reported by Google on 2026-06-12

[N/A][523714535] High CVE-2026-79288: Improper input validation in Autofill. Reported by Google on 2026-06-14

[N/A][523717796] High CVE-2026-79130: Buffer overflow in ANGLE. Reported by Google on 2026-06-14

[N/A][523723064] High CVE-2026-78965: Uninitialized resource in ANGLE. Reported by Google on 2026-06-14

[N/A][523738212] High CVE-2026-79117: Race condition in WebAppInstalls. Reported by Google on 2026-06-14

[N/A][524698525] High CVE-2026-79082: Incorrect authorization in Transactions Platform. Reported by Google on 2026-06-16

[N/A][525683797] High CVE-2026-79111: Improper input validation in Dawn. Reported by Google on 2026-06-19

[N/A][528397177] High CVE-2026-79072: Improper state validation in Performance. Reported by Google on 2026-06-27

[N/A][529509587] High CVE-2026-79142: Buffer overflow in ANGLE. Reported by Google on 2026-06-30

[N/A][529991907] High CVE-2026-78948: Buffer overflow in WebGL. Reported by Google on 2026-07-01

[N/A][532904047] High CVE-2026-78908: Information leak in Canvas. Reported by Google on 2026-07-09

[N/A][532914190] High CVE-2026-78895: Information leak in Paint. Reported by Google on 2026-07-09

[N/A][532988552] High CVE-2026-79043: Out of bounds write in ANGLE. Reported by Google on 2026-07-09

[N/A][534468209] High CVE-2026-79235: Use after free in WebGL. Reported by Google on 2026-07-13

[N/A][534591074] High CVE-2026-79232: Use after free in Aura. Reported by Google on 2026-07-14

[N/A][535379043] High CVE-2026-79118: Uninitialized resource in ANGLE. Reported by Google on 2026-07-16

[TBD][535876894] High CVE-2026-79174: Incorrect authorization in Extensions. Reported by η« ι±Όε“₯@aipyaipy.com on 2026-07-17

[N/A][536428615] High CVE-2026-78900: Improper input validation in Media. Reported by Google on 2026-07-19

[N/A][536444272] High CVE-2026-79188: Out of bounds write in ANGLE. Reported by Google on 2026-07-19

[N/A][536505721] High CVE-2026-79189: Out of bounds write in ANGLE. Reported by Google on 2026-07-19

[N/A][536531630] High CVE-2026-79048: Out of bounds write in ANGLE. Reported by Google on 2026-07-19

[N/A][536532605] High CVE-2026-79240: Out of bounds write in ANGLE. Reported by Google on 2026-07-19

[N/A][536568319] High CVE-2026-79014: Race condition in Autofill. Reported by Google on 2026-07-19

[N/A][536606137] High CVE-2026-79198: Use after free in Platform. Reported by Google on 2026-07-19

[N/A][536626343] High CVE-2026-79131: Out of bounds write in ANGLE. Reported by Google on 2026-07-19

[N/A][536636648] High CVE-2026-79149: Use after free in ANGLE. Reported by Google on 2026-07-19

[N/A][536659904] High CVE-2026-79275: Use after free in ANGLE. Reported by Google on 2026-07-20

[N/A][536681676] High CVE-2026-79138: Out of bounds write in ANGLE. Reported by Google on 2026-07-20

[N/A][537109028] High CVE-2026-79026: Use after free in Extensions. Reported by Google on 2026-07-21

[TBD][537233963] High CVE-2026-79027: Use after free in WebRTC. Reported by Mozilla on 2026-07-21

[N/A][537835609] High CVE-2026-78904: Type confusion in ANGLE. Reported by Google on 2026-07-22

[TBD][540430406] High CVE-2026-78899: Use after free in V8. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern) on 2026-07-29

[N/A][540870921] High CVE-2026-78954: Incorrect authorization in Extensions. Reported by Google on 2026-07-30

[TBD][543707066] High CVE-2026-79274: Information leak in GPU. Reported by weihengqiuu on 2026-08-07

[TBD][545767601] High CVE-2026-78938: Type confusion in V8. Reported by Zhenpeng (Leo) Lin at depthfirst on 2026-08-12

[TBD][545820931] High CVE-2026-78952: Out of bounds write in Crashpad. Reported by Brendan Dolan-Gavitt, XBOW on 2026-08-13

[TBD][546670199] High CVE-2026-79236: Type confusion in V8. Reported by Zhenpeng (Leo) Lin on 2026-08-14

[TBD][548340637] High CVE-2026-79078: Use after free in FedCM. Reported by m0omo0d on 2026-08-18

[$8,000][495021566] Medium CVE-2026-79209: Type confusion in Animation. Reported by ochko on 2026-03-22

[$2,000][40057398] Medium CVE-2026-79030: Observable discrepancy in Autofill. Reported by Young Min Kim (@ylemkimon), CompSec Lab at Seoul National

University on 2021-09-25

[$1,000][536913431] Medium CVE-2026-79216: Buffer overflow in Blink. Reported by Found by XBOW and triaged by AndrΓ©s Luksenberg on 2026-07-20

[N/A][495579602] Medium CVE-2026-79007: Uninitialized resource in GPU. Reported by Google on 2026-03-24

[N/A][495998981] Medium CVE-2026-78893: Information leak in QUIC. Reported by Google on 2026-03-25

[N/A][496195129] Medium CVE-2026-79222: Incorrect authorization in CustomTabs. Reported by Google on 2026-03-25

[N/A][496292729] Medium CVE-2026-79071: Race condition in GPU. Reported by Google on 2026-03-25

[N/A][496395158] Medium CVE-2026-79076: Improper input validation in Sync. Reported by Google on 2026-03-26

[N/A][496401361] Medium CVE-2026-79088: Incorrect authorization in FileSystem. Reported by Google on 2026-03-26

[N/A][497017869] Medium CVE-2026-79104: Missing authorization in Sensor. Reported by Google on 2026-03-27

[N/A][497095313] Medium CVE-2026-79044: Missing authorization in WebAppInstalls. Reported by Google on 2026-03-28

[N/A][497205529] Medium CVE-2026-78958: Uninitialized resource in Skia. Reported by Google on 2026-03-28

[N/A][497269030] Medium CVE-2026-78961: Incorrect authorization in Core. Reported by Google on 2026-03-28

[N/A][497338168] Medium CVE-2026-79262: Incorrect authorization in Network. Reported by Google on 2026-03-29

[N/A][497456156] Medium CVE-2026-79106: Improper input validation in Input. Reported by Google on 2026-03-29

[N/A][497538341] Medium CVE-2026-79176: UI misrepresentation in Extensions. Reported by Google on 2026-03-29

[N/A][497637694] Medium CVE-2026-78966: Externally controlled reference in QUIC. Reported by Google on 2026-03-30

[N/A][497646947] Medium CVE-2026-79186: Incorrect authorization in Network. Reported by Google on 2026-03-30

[N/A][497839983] Medium CVE-2026-79267: Race condition in Workers. Reported by Google on 2026-03-30

[N/A][497854976] Medium CVE-2026-79016: Observable discrepancy in SVG. Reported by Google on 2026-03-30

[N/A][497869284] Medium CVE-2026-79010: Operation on a resource after expiration or release in Network. Reported by Google on 2026-03-30

[N/A][497940451] Medium CVE-2026-79286: Missing authorization in CustomTabs. Reported by Google on 2026-03-30

[N/A][497948894] Medium CVE-2026-78945: Use after free in Views. Reported by Google on 2026-03-30

[N/A][497957278] Medium CVE-2026-78999: Improper privilege management in Navigation. Reported by Google on 2026-03-30

[N/A][498327743] Medium CVE-2026-78941: Information leak in Core. Reported by Google on 2026-03-31

[N/A][498328139] Medium CVE-2026-79032: Improper input validation in Network. Reported by Google on 2026-03-31

[N/A][498367544] Medium CVE-2026-79109: Improper input validation in Printing. Reported by Google on 2026-04-01

[N/A][499007248] Medium CVE-2026-79256: Externally controlled reference in WebView. Reported by Google on 2026-04-02

[N/A][499068536] Medium CVE-2026-79237: Incorrect authorization in Navigation. Reported by Google on 2026-04-02

[N/A][499423269] Medium CVE-2026-78898: Incorrect authorization in Downloads. Reported by Google on 2026-04-04

[N/A][500038021] Medium CVE-2026-78985: Incorrect reference resolution in FileSystem. Reported by Google on 2026-04-06

[N/A][500492844] Medium CVE-2026-79028: Observable discrepancy in Network. Reported by Google on 2026-04-08

[N/A][501331457] Medium CVE-2026-79210: Use after free in Audio. Reported by Google on 2026-04-10

[N/A][501437087] Medium CVE-2026-79046: Race condition in Permissions. Reported by Google on 2026-04-10

[N/A][501572758] Medium CVE-2026-79129: Use after free in Sessions. Reported by Google on 2026-04-11

[N/A][501590191] Medium CVE-2026-78937: Use after free in Search. Reported by Google on 2026-04-11

[N/A][501594511] Medium CVE-2026-78987: Information leak in Canvas. Reported by Google on 2026-04-11

[N/A][501604761] Medium CVE-2026-78990: Use after free in Compositing. Reported by Google on 2026-04-11

[N/A][501637242] Medium CVE-2026-78909: Use after free in Views. Reported by Google on 2026-04-11

[N/A][501661601] Medium CVE-2026-79271: Information leak in DOM. Reported by Google on 2026-04-11

[N/A][501759192] Medium CVE-2026-79144: Information leak in Skia. Reported by Google on 2026-04-11

[N/A][501799770] Medium CVE-2026-79065: Improper input validation in Network. Reported by Google on 2026-04-12

[N/A][502082953] Medium CVE-2026-79192: Improper input validation in Variations. Reported by Google on 2026-04-13

[N/A][502101200] Medium CVE-2026-79140: Use after free in Views. Reported by Google on 2026-04-13

[N/A][502109333] Medium CVE-2026-79128: Use after free in Views. Reported by Google on 2026-04-13

[N/A][502139081] Medium CVE-2026-78942: Incorrect reference resolution in Loader. Reported by Google on 2026-04-13

[N/A][502232151] Medium CVE-2026-79116: Missing authorization in Viz. Reported by Google on 2026-04-13

[N/A][502344135] Medium CVE-2026-79006: Protection mechanism failure in HttpsUpgrades. Reported by Google on 2026-04-14

[N/A][502488051] Medium CVE-2026-79095: Information leak in Payments. Reported by Google on 2026-04-14

[N/A][502805441] Medium CVE-2026-79084: Inadequate encryption strength in Notifications. Reported by Google on 2026-04-15

[N/A][502888857] Medium CVE-2026-78991: Race condition in WebProtect. Reported by Google on 2026-04-15

[N/A][502918844] Medium CVE-2026-79248: Incorrect authorization in Input. Reported by Google on 2026-04-15

[TBD][503013378] Medium CVE-2026-78891: Buffer overflow in WebRTC. Reported by ngrunbaum on 2026-04-15

[N/A][503472696] Medium CVE-2026-79031: Improper resource exposure in Preload. Reported by Google on 2026-04-16

[N/A][503585863] Medium CVE-2026-79110: Missing authorization in Preload. Reported by Google on 2026-04-17

[N/A][503624894] Medium CVE-2026-79136: Incorrect authorization in ServiceWorker. Reported by Google on 2026-04-17

[N/A][503847023] Medium CVE-2026-78907: Incorrect authorization in WebProtect. Reported by Google on 2026-04-17

[N/A][504226770] Medium CVE-2026-79087: Injection in Chrome Tabs. Reported by Google on 2026-04-19

[N/A][504356442] Medium CVE-2026-79231: Buffer overflow in Media. Reported by Google on 2026-04-19

[N/A][504633668] Medium CVE-2026-78969: Uninitialized resource in Video. Reported by Google on 2026-04-20

[N/A][505951430] Medium CVE-2026-79137: Incorrect authorization in Extensions. Reported by Google on 2026-04-24

[N/A][505967344] Medium CVE-2026-79057: Race condition in Start. Reported by Google on 2026-04-24

[N/A][505991181] Medium CVE-2026-78894: Race condition in Payments. Reported by Google on 2026-04-24

[N/A][507483993] Medium CVE-2026-79264: Incorrect reference resolution in Preload. Reported by Google on 2026-04-28

[N/A][511260796] Medium CVE-2026-78910: Buffer overflow in V8. Reported by Google on 2026-05-08

[N/A][511736672] Medium CVE-2026-79066: Improper input validation in Navigation. Reported by Google on 2026-05-10

[N/A][511794959] Medium CVE-2026-79255: Improper input validation in WebRTC. Reported by Google on 2026-05-10

[N/A][511804361] Medium CVE-2026-79086: Missing authorization in CustomTabs. Reported by Google on 2026-05-10

[N/A][511806043] Medium CVE-2026-79038: Incorrect authorization in WebProtect. Reported by Google on 2026-05-10

[N/A][511819962] Medium CVE-2026-78940: Improper initialization in Network. Reported by Google on 2026-05-10

[N/A][511822878] Medium CVE-2026-79107: Incorrect authorization in TabGroups. Reported by Google on 2026-05-10

[N/A][512971896] Medium CVE-2026-79120: Uninitialized resource in ANGLE. Reported by Google on 2026-05-13

[N/A][513048462] Medium CVE-2026-79270: Uninitialized resource in ANGLE. Reported by Google on 2026-05-14

[N/A][513049445] Medium CVE-2026-79067: Missing authorization in Network. Reported by Google on 2026-05-14

[N/A][513119757] Medium CVE-2026-79213: Incorrect authorization in WebAppInstalls. Reported by Google on 2026-05-14

[N/A][513192145] Medium CVE-2026-78943: Improper input validation in Editing. Reported by Google on 2026-05-14

[N/A][513222422] Medium CVE-2026-79259: Improper input validation in Safebrowsing. Reported by Google on 2026-05-14

[N/A][513287677] Medium CVE-2026-79208: Missing authorization in HTTP2. Reported by Google on 2026-05-14

[N/A][513392351] Medium CVE-2026-79251: Improper input validation in Network. Reported by Google on 2026-05-15

[N/A][513607252] Medium CVE-2026-79226: Improper privilege management in Regional Capabilities. Reported by Google on 2026-05-15

[N/A][513608317] Medium CVE-2026-79042: Missing authorization in Payments. Reported by Google on 2026-05-15

[N/A][513608831] Medium CVE-2026-79122: Information leak in SignIn. Reported by Google on 2026-05-15

[N/A][513719741] Medium CVE-2026-79199: Incorrect authorization in Network. Reported by Google on 2026-05-16

[N/A][513737209] Medium CVE-2026-79013: Improper input validation in Sync. Reported by Google on 2026-05-16

[N/A][513745793] Medium CVE-2026-79074: Information leak in Network. Reported by Google on 2026-05-16

[N/A][513760788] Medium CVE-2026-79215: Integer overflow in WebGL. Reported by Google on 2026-05-16

[N/A][513786555] Medium CVE-2026-79049: Incorrect reference resolution in Passwords. Reported by Google on 2026-05-16

[N/A][513834155] Medium CVE-2026-79132: Improper input validation in Input. Reported by Google on 2026-05-16

[N/A][513836495] Medium CVE-2026-79201: Improper access control in Workers. Reported by Google on 2026-05-16

[N/A][513841856] Medium CVE-2026-79051: Incorrect authorization in Loader. Reported by Google on 2026-05-16

[N/A][513850062] Medium CVE-2026-79053: Missing authorization in Lighthouse. Reported by Google on 2026-05-16

[N/A][513918923] Medium CVE-2026-79285: Uninitialized resource in ANGLE. Reported by Google on 2026-05-17

[N/A][513923164] Medium CVE-2026-78906: Race condition in ANGLE. Reported by Google on 2026-05-17

[N/A][514006744] Medium CVE-2026-79250: UI misrepresentation in Navigation. Reported by Google on 2026-05-17

[N/A][514017820] Medium CVE-2026-79020: Out of bounds read in Skia. Reported by Google on 2026-05-17

[N/A][514055709] Medium CVE-2026-79217: Incorrect authorization in Mobile. Reported by Google on 2026-05-17

[N/A][514069975] Medium CVE-2026-79204: UI misrepresentation in Input. Reported by Google on 2026-05-17

[N/A][514078852] Medium CVE-2026-78912: UI misrepresentation in Browser. Reported by Google on 2026-05-17

[N/A][514439436] Medium CVE-2026-78955: Observable discrepancy in PerformanceAPIs. Reported by Google on 2026-05-18

[N/A][514454739] Medium CVE-2026-79143: Incorrect authorization in FileSystem. Reported by Google on 2026-05-19

[N/A][514508415] Medium CVE-2026-79241: Out of bounds read in GPU. Reported by Google on 2026-05-19

[N/A][514529599] Medium CVE-2026-78967: Missing authorization in BFCache. Reported by Google on 2026-05-19

[N/A][515477007] Medium CVE-2026-79214: Improper input validation in Preload. Reported by Google on 2026-05-21

[N/A][516398679] Medium CVE-2026-79228: Incorrect authorization in SiteIsolation. Reported by Google on 2026-05-25

[N/A][516665605] Medium CVE-2026-78953: Missing authorization in SiteIsolation. Reported by Google on 2026-05-26

[N/A][516824665] Medium CVE-2026-79229: Uninitialized resource in ANGLE. Reported by Google on 2026-05-26

[N/A][516899248] Medium CVE-2026-79002: Incorrect authorization in SiteIsolation. Reported by Google on 2026-05-26

[N/A][516921259] Medium CVE-2026-79272: Improper input validation in FindInPage. Reported by Google on 2026-05-27

[N/A][517045394] Medium CVE-2026-79127: Out of bounds write in ANGLE. Reported by Google on 2026-05-27

[N/A][517074167] Medium CVE-2026-79151: Improper input validation in Safebrowsing. Reported by Google on 2026-05-27

[N/A][517095594] Medium CVE-2026-78936: Observable discrepancy in CustomTabs. Reported by Google on 2026-05-27

[N/A][517245017] Medium CVE-2026-78905: Type confusion in ANGLE. Reported by Google on 2026-05-27

[N/A][517364411] Medium CVE-2026-79050: Incorrect authorization in Network. Reported by Google on 2026-05-28

[N/A][517382613] Medium CVE-2026-79008: Improper input validation in GPU. Reported by Google on 2026-05-28

[N/A][517398863] Medium CVE-2026-78975: Incorrect authorization in DOM. Reported by Google on 2026-05-28

[N/A][517404644] Medium CVE-2026-79287: Observable discrepancy in Forms. Reported by Google on 2026-05-28

[N/A][517467117] Medium CVE-2026-79094: Race condition in Workers. Reported by Google on 2026-05-28

[N/A][517487890] Medium CVE-2026-79173: UI misrepresentation in WebAppInstalls. Reported by Google on 2026-05-28

[N/A][517550421] Medium CVE-2026-78976: Improper input validation in StorageAccessAPI. Reported by Google on 2026-05-28

[N/A][517580738] Medium CVE-2026-79276: Improper privilege management in FileSystem. Reported by Google on 2026-05-28

[N/A][517606780] Medium CVE-2026-79191: Incorrect authorization in SiteIsolation. Reported by Google on 2026-05-28

[N/A][517608454] Medium CVE-2026-79099: Missing authorization in Network. Reported by Google on 2026-05-28

[N/A][517634590] Medium CVE-2026-79024: Information leak in ServiceWorker. Reported by Google on 2026-05-28

[N/A][517655953] Medium CVE-2026-79193: Information leak in Canvas. Reported by Google on 2026-05-28

[N/A][517697155] Medium CVE-2026-79242: Observable discrepancy in HTML. Reported by Google on 2026-05-29

[N/A][517719358] Medium CVE-2026-79180: UI misrepresentation in CustomTabs. Reported by Google on 2026-05-29

[N/A][517746687] Medium CVE-2026-79293: Information leak in Animation. Reported by Google on 2026-05-29

[N/A][517761566] Medium CVE-2026-79023: Incorrect authorization in Editing. Reported by Google on 2026-05-29

[N/A][517772510] Medium CVE-2026-79146: Information leak in CustomTabs. Reported by Google on 2026-05-29

[N/A][517774971] Medium CVE-2026-79238: Incorrect authorization in ServiceWorker. Reported by Google on 2026-05-29

[N/A][517910756] Medium CVE-2026-78949: Observable discrepancy in CustomTabs. Reported by Google on 2026-05-29

[N/A][518023156] Medium CVE-2026-79291: Information leak in CSS. Reported by Google on 2026-05-29

[N/A][518035396] Medium CVE-2026-79283: UI misrepresentation in Geometry. Reported by Google on 2026-05-29

[N/A][518053893] Medium CVE-2026-78892: Incorrect authorization in Chromoting. Reported by Google on 2026-05-30

[N/A][518062961] Medium CVE-2026-79070: Incorrect reference resolution in Cache. Reported by Google on 2026-05-30

[N/A][518065628] Medium CVE-2026-79205: Incorrect authorization in Network. Reported by Google on 2026-05-30

[N/A][518078552] Medium CVE-2026-78903: Incomplete cleanup in SiteIsolation. Reported by Google on 2026-05-30

[N/A][518084889] Medium CVE-2026-78959: Improper handling of case sensitivity in FileSystem. Reported by Google on 2026-05-30

[N/A][518094442] Medium CVE-2026-79234: Injection in CSS. Reported by Google on 2026-05-30

[N/A][519369088] Medium CVE-2026-78983: Use after free in Views. Reported by Google on 2026-06-03

[N/A][519984038] Medium CVE-2026-79083: Improper enforcement of behavioral workflow in Media. Reported by Google on 2026-06-04

[TBD][520052954] Medium CVE-2026-78944: Use after free in DevTools. Reported by yupyon.itome on 2026-06-05

[N/A][520117546] Medium CVE-2026-79178: Incorrect authorization in Web Authentication (Passkeys & Security Keys). Reported by Google on 2026-06-04

[N/A][520121111] Medium CVE-2026-79059: Information leak in BFCache. Reported by Google on 2026-06-04

[N/A][520179360] Medium CVE-2026-79245: Use after free in UI. Reported by Google on 2026-06-05

[N/A][520464738] Medium CVE-2026-78978: Out of bounds read in ANGLE. Reported by Google on 2026-06-05

[N/A][520481800] Medium CVE-2026-79103: Incorrect reference resolution in Speech. Reported by Google on 2026-06-05

[N/A][520492291] Medium CVE-2026-79154: Missing authorization in DevTools. Reported by Google on 2026-06-05

[N/A][520504922] Medium CVE-2026-79230: Improper input validation in ANGLE. Reported by Google on 2026-06-05

[N/A][520516462] Medium CVE-2026-79068: Improper resource exposure in StreamsAPI. Reported by Google on 2026-06-05

[N/A][520542088] Medium CVE-2026-79269: Uninitialized resource in ANGLE. Reported by Google on 2026-06-05

[N/A][522077127] Medium CVE-2026-79085: Missing authorization in Network. Reported by Google on 2026-06-10

[N/A][522351802] Medium CVE-2026-79134: Incorrect authorization in GetUserMedia. Reported by Google on 2026-06-10

[N/A][522550059] Medium CVE-2026-79064: Use after free in Network. Reported by Google on 2026-06-11

[N/A][522791354] Medium CVE-2026-79003: Incorrect authorization in Device. Reported by Google on 2026-06-11

[N/A][522823211] Medium CVE-2026-79220: Information leak in Network. Reported by Google on 2026-06-11

[N/A][522957054] Medium CVE-2026-78951: Use after free in ServiceWorker. Reported by Google on 2026-06-11

[N/A][523232966] Medium CVE-2026-79249: Code injection in Bisection. Reported by Google on 2026-06-12

[N/A][523557855] Medium CVE-2026-79091: Use after free in Bluetooth. Reported by Google on 2026-06-13

[N/A][523661149] Medium CVE-2026-79265: Incomplete cleanup in GetUserMedia. Reported by Google on 2026-06-13

[N/A][523716748] Medium CVE-2026-78913: Use after free in Chromoting. Reported by Google on 2026-06-14

[N/A][524418836] Medium CVE-2026-79258: Incorrect authorization in WebXR. Reported by Google on 2026-06-16

[TBD][524520965] Medium CVE-2026-79211: Incorrect authorization in USB. Reported by hongan on 2026-06-16

[N/A][524541667] Medium CVE-2026-79252: Information leak in ServiceWorker. Reported by Google on 2026-06-16

[N/A][524822825] Medium CVE-2026-78962: Uninitialized resource in WebXR. Reported by Google on 2026-06-17

[N/A][525686865] Medium CVE-2026-78901: Race condition in V8. Reported by Google on 2026-06-19

[N/A][525689847] Medium CVE-2026-79097: Use after free in V8. Reported by Google on 2026-06-19

[N/A][532162132] Medium CVE-2026-79227: Type confusion in DevTools. Reported by Google on 2026-07-07

[N/A][532182486] Medium CVE-2026-79203: Improper input validation in DevTools. Reported by Google on 2026-07-07

[N/A][532914769] Medium CVE-2026-79033: Insufficient control flow management in DevTools. Reported by Google on 2026-07-09

[N/A][532917452] Medium CVE-2026-79139: Improper input validation in Media. Reported by Google on 2026-07-09

[N/A][532923954] Medium CVE-2026-79221: Uninitialized resource in Dawn. Reported by Google on 2026-07-09

[N/A][532957785] Medium CVE-2026-79034: Information leak in CORS. Reported by Google on 2026-07-09

[N/A][533093250] Medium CVE-2026-79075: Information leak in Geolocation. Reported by Google on 2026-07-09

[TBD][533917984] Medium CVE-2026-78960: Information leak in Extensions. Reported by Oran Simhony from Palo Alto Networks on 2026-07-12

[N/A][535374213] Medium CVE-2026-78984: Uninitialized resource in GPU. Reported by Google on 2026-07-16

[N/A][536428842] Medium CVE-2026-78963: Improper input validation in Media. Reported by Google on 2026-07-19

[N/A][536428988] Medium CVE-2026-79004: Out of bounds read in Media. Reported by Google on 2026-07-19

[N/A][536444242] Medium CVE-2026-79182: Improper input validation in Media. Reported by Google on 2026-07-19

[TBD][536526176] Medium CVE-2026-79185: Information leak in DOM. Reported by avlidienbrunn on 2026-07-19

[N/A][536662911] Medium CVE-2026-79073: Improper state validation in Parser. Reported by Google on 2026-07-20

[N/A][537145191] Medium CVE-2026-79266: Use after free in DevTools. Reported by Google on 2026-07-21

[N/A][537846307] Medium CVE-2026-79025: Improper input validation in Workers. Reported by Google on 2026-07-22

[TBD][538969297] Medium CVE-2026-79141: Incorrect authorization in Browser. Reported by M. Fauzan Wijaya (Gh05t666nero) on 2026-07-25

[$1,000][503048520] Low CVE-2026-78974: UI misrepresentation in Linux Toolkit Theming. Reported by Francesco Topol on 2026-04-16

[N/A][497232609] Low CVE-2026-79055: Information leak in Sharing. Reported by Google on 2026-03-28

[N/A][497256260] Low CVE-2026-79263: Race condition in Extensions. Reported by Google on 2026-03-28

[N/A][497493136] Low CVE-2026-79124: Information leak in Intents. Reported by Google on 2026-03-29

[N/A][497499482] Low CVE-2026-79184: Missing authorization in Preload. Reported by Google on 2026-03-29

[N/A][497876969] Low CVE-2026-79289: Improper control of a resource through its lifetime in Workers. Reported by Google on 2026-03-30

[N/A][500484520] Low CVE-2026-79001: Information leak in Bluetooth. Reported by Google on 2026-04-07

[N/A][501416859] Low CVE-2026-79077: Incorrect authorization in WebProtect. Reported by Google on 2026-04-10

[TBD][501881082] Low CVE-2026-78950: Integer overflow in WebRTC. Reported by Ashutosh on 2026-04-12

[N/A][502252964] Low CVE-2026-79196: Race condition in Editing. Reported by Google on 2026-04-13

[N/A][502514083] Low CVE-2026-79000: Improper input validation in DeviceBoundSessionCredentials. Reported by Google on 2026-04-14

[N/A][503720291] Low CVE-2026-78979: Race condition in Core. Reported by Google on 2026-04-17

[N/A][506539337] Low CVE-2026-79181: Observable discrepancy in Glic. Reported by Google on 2026-04-26

[N/A][513172858] Low CVE-2026-79190: Incorrect authorization in Extensions. Reported by Google on 2026-05-14

[N/A][513361380] Low CVE-2026-79206: Out of bounds read in FileSystem. Reported by Google on 2026-05-15

[N/A][513486883] Low CVE-2026-78897: Missing authorization in BrowserTag. Reported by Google on 2026-05-15

[N/A][513688690] Low CVE-2026-79119: Use after free in PDF. Reported by Google on 2026-05-15

[N/A][513792983] Low CVE-2026-79089: Race condition in Transactions Platform. Reported by Google on 2026-05-16

[N/A][513969378] Low CVE-2026-79147: Information leak in Skia. Reported by Google on 2026-05-17

[N/A][514010111] Low CVE-2026-79098: UI misrepresentation in PermissionElement. Reported by Google on 2026-05-17

[N/A][514038302] Low CVE-2026-79022: UI misrepresentation in Transactions Platform. Reported by Google on 2026-05-17

[N/A][514061923] Low CVE-2026-79233: UI misrepresentation in CustomTabs. Reported by Google on 2026-05-17

[N/A][514408247] Low CVE-2026-79261: Incorrect authorization in Controls. Reported by Google on 2026-05-18

[N/A][516864349] Low CVE-2026-78977: Uninitialized resource in GPU. Reported by Google on 2026-05-26

[N/A][516950646] Low CVE-2026-79040: Uninitialized resource in GPU. Reported by Google on 2026-05-27

[N/A][517167020] Low CVE-2026-79273: Incorrect reference resolution in WebView. Reported by Google on 2026-05-27

[TBD][517394060] Low CVE-2026-79243: Improper input validation in ReadingList. Reported by Orange Tsai (@orange_8361) of DEVCORE Research Team on 2026-05-28

[TBD][517395590] Low CVE-2026-79123: Improper input validation in NTP Footer. Reported by Orange Tsai (@orange_8361) of DEVCORE Research Team on 2026-05-28

[N/A][517540292] Low CVE-2026-79005: Incorrect authorization in StorageAccessAPI. Reported by Google on 2026-05-28

[N/A][517673944] Low CVE-2026-79090: Improper privilege management in Actor. Reported by Google on 2026-05-29

[N/A][517718241] Low CVE-2026-78946: Incorrect authorization in Select. Reported by Google on 2026-05-29

[N/A][518125889] Low CVE-2026-78968: Missing authorization in Core. Reported by Google on 2026-05-30

[N/A][518249083] Low CVE-2026-79041: Missing authorization in Browser. Reported by Google on 2026-05-30

[N/A][519210950] Low CVE-2026-79284: UI misrepresentation in Core. Reported by Google on 2026-06-02

[N/A][519229463] Low CVE-2026-78896: Information leak in StorageAccessAPI. Reported by Google on 2026-06-02

[N/A][519242511] Low CVE-2026-79058: Missing authorization in Passwords. Reported by Google on 2026-06-02

[N/A][519246298] Low CVE-2026-79009: UI misrepresentation in UI. Reported by Google on 2026-06-02

[N/A][519254827] Low CVE-2026-79060: Incorrect authorization in StorageAccessAPI. Reported by Google on 2026-06-02

[N/A][520002854] Low CVE-2026-79177: Incorrect authorization in Media. Reported by Google on 2026-06-04

[N/A][520016142] Low CVE-2026-78956: Type confusion in V8. Reported by Google on 2026-06-04

[TBD][520781436] Low CVE-2026-79239: Out of bounds read in Tint. Reported by Michal Andryskowski, Imperial College London on 2026-06-07

[N/A][522291712] Low CVE-2026-79015: Improper input validation in ServiceWorker. Reported by Google on 2026-06-10

[N/A][522304549] Low CVE-2026-79108: UI misrepresentation in Web Authentication (Passkeys & Security Keys). Reported by Google on 2026-06-10

[N/A][522418913] Low CVE-2026-79056: Use after free in ServiceWorker. Reported by Google on 2026-06-10

[N/A][522803735] Low CVE-2026-79018: Information leak in FoldableAPIs. Reported by Google on 2026-06-11

[N/A][523237735] Low CVE-2026-78980: Improper input validation in ReaderMode. Reported by Google on 2026-06-12

[N/A][523313378] Low CVE-2026-78947: Incomplete cleanup in Chromium. Reported by Microsoft Edge on 2026-06-12

[N/A][523572877] Low CVE-2026-79244: Use after free in Animation. Reported by Google on 2026-06-13

[TBD][524864599] Low CVE-2026-79112: Out of bounds read in Skia. Reported by Quan Huynh x Amaterasu on 2026-06-17

[N/A][525311654] Low CVE-2026-79246: Information leak in DataTransfer. Reported by Google on 2026-06-18

[TBD][530816571] Low CVE-2026-79223: Integer overflow in Chromium. Reported by Youngjin Ju on 2026-07-03

[N/A][531245718] Low CVE-2026-79045: Type confusion in V8. Reported by Google on 2026-07-04

[N/A][531297707] Low CVE-2026-79197: Use after free in V8. Reported by Google on 2026-07-05

[N/A][532303080] Low CVE-2026-79148: Off-by-one error in DevTools. Reported by Google on 2026-07-08

[N/A][533001362] Low CVE-2026-79125: Information leak in XR. Reported by Google on 2026-07-09

[N/A][533014006] Low CVE-2026-79207: Information leak in Passwords. Reported by Google on 2026-07-09

[N/A][533021205] Low CVE-2026-79017: Race condition in Extensions. Reported by Google on 2026-07-09

[N/A][533046298] Low CVE-2026-79105: Improper input validation in Mobile. Reported by Google on 2026-07-09

[N/A][533059149] Low CVE-2026-79225: Incorrect authorization in Browser. Reported by Google on 2026-07-09

[N/A][533060125] Low CVE-2026-79021: Missing authorization in InterestGroups. Reported by Google on 2026-07-09

[N/A][533075126] Low CVE-2026-79133: Incorrect authorization in Forms. Reported by Google on 2026-07-09

[N/A][533079345] Low CVE-2026-79179: Incorrect authorization in DOM. Reported by Google on 2026-07-09

[N/A][533083384] Low CVE-2026-79152: Incorrect authorization in CustomTabs. Reported by Google on 2026-07-09

[N/A][533121405] Low CVE-2026-78981: Information leak in Mobile. Reported by Google on 2026-07-09

[N/A][533123348] Low CVE-2026-78957: Information leak in Mobile. Reported by Google on 2026-07-09

[N/A][533408915] Low CVE-2026-79126: Incorrect provision of specified functionality in Proxy. Reported by Google on 2026-07-10

[N/A][533418127] Low CVE-2026-78915: Race condition in Enterprise. Reported by Google on 2026-07-10

[N/A][533511921] Low CVE-2026-79253: Improper input validation in Network. Reported by Google on 2026-07-10

[N/A][533511967] Low CVE-2026-79260: Improper input validation in Cookies. Reported by Google on 2026-07-10

[N/A][534556413] Low CVE-2026-79254: Incorrect reference resolution in CustomTabs. Reported by Google on 2026-07-14

[N/A][536166543] Low CVE-2026-78914: Uninitialized resource in Skia. Reported by Google on 2026-07-18

[N/A][539341100] Low CVE-2026-78964: Use after free in Sync. Reported by Google on 2026-07-27


We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.


Many of our security bugs are detected using AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, or AFL.


Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.


Srinivas Sista

Google Chrome

  •  

Firefox 154.0.1

25 Augustus 2026 om 17:40

Fixed

  • Fixed slower access to saved passwords and unexpected Primary Password prompts caused by recent changes to password storage. (Bug 2064411, Bug 2065593, Bug 2063993)

  • Fixed an issue where addresses were failing to autofill on some sites. (Bug 2065145, Bug 2063599)

  • Fixed Firefox adding a new Start Menu shortcut on Windows every time it started. (Bug 2064652)

  • Fixed an issue where connections to local network devices were failing without a permission prompt on some sites loaded over HTTP. (Bug 2059274)

  • Fixed a crash that could occur when opening intranet sites that are configured to link to files on a local network share. (Bug 2064648)

  • Fixed an issue on Windows where tab titles were cut off at the start when the system font was MS UI Gothic. (Bug 2056856)

Unresolved

  • For users with vertical tabs enabled, the sidebar may not persist across Firefox restarts. Vertical tabs can be re-enabled after the restart by clicking the sidebar toolbar button. A fix is available in Firefox 155.0.1.

  • When toolbars are hidden in fullscreen mode (the default on Windows and Linux), the vertical tabs sidebar does not appear when moving the cursor to the left edge of the screen. As a workaround, move the cursor to the top of the screen to reveal both toolbars and sidebar together. Alternatively, you can also right-click the toolbar and uncheck the Hide toolbars option. We are currently working on a fix. (Bug 2064638)

  •  

2.8.1

Door: clsid2
22 Augustus 2026 om 21:28

Donations are appreciated. There is now a PayPal option.

Changes from 2.8.0 to 2.8.1:

Updates:

  • Updated LAV Filters to version 0.83-1-g63d24
  • Updated MPC Video Renderer to version 0.10.8.2572

Changes/additions:

  • Added ability to load a secondary subtitle track from the subtitle menu. This supports only external text-based formats (SRT) and excludes formats that may contain explicit positioning (SSA/PGS/VobSub). The secondary subtitle is rendered at the top of the window. There are some known limitations. For example adjustments such as delay will apply to both tracks. Secondary is also not included in screenshots. Do NOT open issues/requests about this!
  • Added ability to auto-copy all rendered subtitle text to the clipboard in real-time. Toggling this on/off can be assigned to a hotkey or one of the custom toolbar buttons.
  • New "remote" page in web interface, providing a modern interface for remote control of MPC-HC from any phone (or web browser) in your local network.
  • Expanded the API for remote control through window messages from a master process. See MpcApi.h header file.

Fixes:

  • A few bug fixes in web interface.
  • A few other fixes and small improvements.

Full changelog

Full list of all changes since start of this project.

OpenSubtitles download error 406

Subtitle downloads from OpenSubtitles may fail depending on time of day. This is due to our daily download quota being exceeded. Current amount of donations is barely enough to pay for the existing quota. So it is unlikely that quota can be increased and situation will get worse over time.
If you create an OpenSubtitles account and configure it in MPC-HC settings then you may be able to bypass the quota.
Options > Subtitles > Misc > Right-click on OpenSubtitles.com > Setup > Fill in username/password

Overview of features

A lot of people seem to be unaware of some of the awesome features that have been added to MPC-HC in the past years. Here is a list of useful options and features that everyone should know about:

  • Play HDR video
    This requires using either MPC Video Renderer (MPCVR) or madVR.
    These renderers can be selected here:
    Options > Playback > Output
    With other video renderers, the colors will be wrong!
    MPCVR is included and is the recommended and default renderer for modern systems. MadVR needs to be installed separately. MPCVR also supports Dolby Vision. MadVR does not.
    For optimal performance you should change the hardware decoder to D3D11 in LAV Video Decoder settings when using MPCVR on Windows 10/11, because this renderer uses DirectX11.
  • The installer of MPC-HC is very basic (and that will not change).
    I therefore recommend using K-Lite Codec Pack. That includes MPC-HC and other essential components. It has a very advanced installation that can automatically create file associations, and helps you with easy configuration of important MPC-HC settings, such as preferred subtitle language(s). It also does automatic configuration of renderer and hardware decoding, for best performance and HDR support.
    The Standard version should be sufficient for most people. Use Full version of you like to use MadVR.
  • Modern GUI Theme (Dark or Light) or the old classic theme
    Options > Player > User Interface
    It is also possible to change the height of the seekbar and size of the toolbar buttons.
    Plus there are options to show audio/video details in the statusbar, such as codec and resolution.
  • Customizable toolbar buttons
    You can add/remove/re-order the player buttons.
    There are also several different toolbar designs to choose from.
  • Video preview on the seekbar
    Options > Player > User Interface > Hover type
  • Ability to search for subtitles
    Press D for manual search.
    Or enable automatic search in: Options > Subtitles > Misc
  • Adjust playback speed
    Menu > Play > Playback rate
    The buttons in the player that control playback rate take a 2x step by default. This can be customized to smaller values (like 10%):
    Options > Playback > Speed step
    If you have 1000 IQ you can even do smart stuff like setting playback rate change to mouse right-click + scrollwheel:
    Options > Player > Mouse
    Adjusting playback speed works best with MPC Audio Renderer or SaneAR. These audio renderers have automatic pitch correction, while DirectSound does not.
    Options > Playback > Output > Audio Renderer
  • MPC-HC can remember recently played files and also their playback position, so you can resume playback from when you left
    Options > Player > History
  • You can quickly seek through a video with Ctrl + Mouse Scrollwheel.
  • You can jump to next/previous file in a folder by pressing PageUp/PageDown.
  • You can right-click on the framestep button to step backwards. Some other buttons also have right-click actions, such as closing file by right-clicking stop.
  • You can perform automatic actions at end of file. For example to go to next file or close player.
    Options > Playback > After Playback (permanent setting)
    Menu > Play > After Playback (for current file only)
  • A-B repeat
    You can loop a segment of a video. Press [ and ] to set start and stop markers.
  • You can rotate/flip/mirror/stretch/zoom the video
    Menu > View > Pan&Scan
    This is also easily done with hotkeys (see below).
  • There are lots of keyboard hotkeys and mouse actions to control the player. They can be customized as well.
    Options > Player > Keys
    Tip: there is a search box above the table.
  • You can hide GUI elements even in windowed mode
    Options > User Interface > Hide Windowed Controls
    That hides most GUI elements during playback. To show them simply move your mouse to bottom of window.
    You can even hide everything except the video by pressing 1 (restore normal view with 3).
  • You can seek inside the playlist by simply typing text (when playlist window has the mouse focus).
  • MPC-HC also supports Blu-ray playback.
    Only limitation is that you need to use a decrypting tool.
    And it also does not support Blu-ray menus, but you can use the navigate menu in the player to select the content to play.
  • You can stream videos directly from Youtube and many other video websites
    Put yt-dlp.exe in the MPC-HC installation folder.
    Then you can open website URLs in the player: Menu > File > Open File/URL
    You can even download those videos: Menu > File > Save a copy
    Tip: to be able to download in best quality with yt-dlp, it is recommended to also put ffmpeg.exe in the MPC-HC folder.
    Several YDL configuration options are found here: Options > Advanced
    This includes an option to specify the location of yt-dlp.exe in case you don't want to put it in MPC-HC folder.
    Note 1: You also need to install Microsoft Visual C++ 2010 SP1 Redistributable Package (x86)
    Note 2: For optimal Youtube support you may also need to put deno.exe in same folder as yt-dlp.
    Note 3: yt-dlp nightly build (very latest version made daily)
    Note 4: yt-dlp windows7 compatible build
  • Besides all these (new) features, there have also been many bugfixes and internal improvements in the player in the past years that give better performance and stability. It also has updated internal codecs. Support was added for CUE sheets, WebVTT subtitles, etc.
  • You should really take a few minutes to look through all the options pages if you are a new user or if you are upgrading from a very old version. Don't forget the advanced options page.

MPC Video Renderer

Frequently Asked Questions

  •  

Stable Channel Update for Desktop

20 Augustus 2026 om 22:28

The Stable channel has been updated to 151.0.7922.173/.174 for Windows and Mac and 151.0.7922.173 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available in the LogΒ 

Security Fixes and Rewards

Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.

This update includes 7 security fixes. Please see the Chrome Security Page for more information.


[N/A][522819252] Critical CVE-2026-76017: Use after free in Chromoting. Reported by Google on 2026-06-11

[N/A][513757918] High CVE-2026-76018: Privilege elevation in Import. Reported by Google on 2026-05-16

[TBD][539032888] High CVE-2026-76019: Incorrect authorization in Workers. Reported by Anonymous on 2026-07-26

[TBD][541837151] High CVE-2026-76020: Race condition in V8. Reported by Salvatore Gulizia (nickname: Serotav) on 2026-08-03

[N/A][541854084] High CVE-2026-76021: Use after free in DOM. Reported by Google BigSleep@Grape on 2026-08-02

[TBD][543798025] High CVE-2026-76022: Buffer overflow in Network. Reported by 0xAlessandro on 2026-08-07

[TBD][545124048] High CVE-2026-76023: Improper resource control in Linux Toolkit Theming. Reported by Keita Sode and Daisuke Hatakeyama of SYZD Research on 2026-08-11


We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.


Many of our security bugs are detected using AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, or AFL.

Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.


Srinivas Sista

Google Chrome

  •  

Firefox 151.0.4

9 Juni 2026 om 18:01

Fixed

  • Fixed an issue on Windows where Firefox could become unresponsive when using the back and forward buttons. (Bug 2039866)

  • Fixed an issue where Firefox could fall back to software rendering on some older GPUs, reducing graphics performance. (Bug 2043249)

  • Fixed a crash on Windows that could occur when Firefox interacted with accessibility services. (Bug 204330)

  • Fixed an issue where some text input fields could incorrectly show a resize handle. (Bug 2044051)

  •  

CPU-Z 3.01

20 Augustus 2026 om 18:00
  • CPU-Z Validator V3 (more information *at that address*).
  •  

Dopamine 3.0.9

Door: digimezzo
19 Augustus 2026 om 20:56

[3.0.9] - 2026-08-19

Added

  • Added an equalizer
  • Added a clear selection button on artists, genres, albums, playlist folders and playlists screens.
  • Added an option to show a more compact total duration in songs lists

Changed

  • Updated the Portuguese (Brazil) translation

Fixed

  • Crash on startup when failing to get the system color when "Follow system color" is enabled
  • Snap version does not start on the first launch
  • Artists whose names start with accented letters (e.g. Ş, Ü) incorrectly grouped under # instead of their base letter in the artists list
  • Tracks of multi-disc albums were grouped by disc number across albums instead of being listed per album
  • When sorting large playlists, songs sometimes move back to their original position.
  • Newline character not processed correctly on some lyrics

  •  

Early Stable Update for Desktop

19 Augustus 2026 om 18:58

The Stable channel has been updated to 152.0.7977.54/.55 for Windows and Mac as part of our early stable release to a small percentage of users. A full list of changes in this build is available in the log.

You can find more details about early Stable releases here.

Interested in switching release channels? Β Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.


Daniel Yip

Google Chrome

  •  

FileZilla Client 3.71.0 released

Door: Tim Kosse
19 Augustus 2026 om 15:50

New features:

  • FTP(S), SFTP: Entering an empty path in the remote path edit field now returns back to the initial home directory

Bugfixes and minor changes:

  • FTP(S): Fix parsing of permissions for chmod dialog on servers that include both perms and unix.mode facts in MLSD output
  • SFTP: Updated fzssh to 1.4.0 to support additional algorithms and key file formats
  • Official binaries are now linked against wxWidgets 3.2.11
  • FTP(S): Fixed parsing of paths on servers with the server type set to DOS. Some malformed paths were wrongly accepted, confusing the engine; such paths are now rejected early.
  • Refactored engine internals to remove influences from FTP-specific concepts that were permeating into other protocols
  •  

Stable Channel Update for Desktop

18 Augustus 2026 om 22:13

Β The Stable channel has been updated to 151.0.7922.169/.170 for Windows and Mac and 151.0.7922.169 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available in the LogΒ 

Security Fixes and Rewards

Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.

This update includes 15 security fixes. Please see the Chrome Security Page for more information.


[N/A][534923522] Critical CVE-2026-76034: Buffer overflow in WebGL. Reported by Google on 2026-07-15

[N/A][540087398] Critical CVE-2026-76036: Buffer overflow in Dawn. Reported by Google on 2026-07-28

[N/A][516715010] High CVE-2026-76033: Inappropriate implementation in CORS. Reported by Google on 2026-05-26

[N/A][517612295] High CVE-2026-76037: Link following in CredentialProvider. Reported by Google on 2026-05-28

[N/A][522732244] High CVE-2026-76044: Race condition in USB. Reported by Google on 2026-06-11

[N/A][525167753] High CVE-2026-76039: Incorrect reference resolution in Core. Reported by Google on 2026-06-18

[N/A][534862220] High CVE-2026-76040: Use after free in Browser. Reported by Google on 2026-07-14

[N/A][536439844] High CVE-2026-76035: Inappropriate implementation in Media. Reported by Google on 2026-07-19

[N/A][536460270] High CVE-2026-76042: Use of uninitialized resource in GPU. Reported by Google on 2026-07-19

[N/A][536581050] High CVE-2026-76046: Buffer overflow in ANGLE. Reported by Google on 2026-07-19

[TBD][539350801] High CVE-2026-76043: Incorrect calculation in V8. Reported by Raghav Maheshwari on 2026-07-27

[N/A][540027341] High CVE-2026-76041: Information leak in Skia. Reported by Google on 2026-07-28

[TBD][541251902] High CVE-2026-76047: Type confusion in V8. Reported by ywatanabee on 2026-07-31

[TBD][541926503] High CVE-2026-76038: Type confusion in V8. Reported by un3xploitable && GF on 2026-08-03

[TBD][543082390] High CVE-2026-76045: Use after free in WebGL. Reported by OpenAI Codex Security (amyb) on 2026-08-05


We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.


Many of our security bugs are detected using AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, or AFL.

Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.


Srinivas Sista

Google Chrome

  •  

Extended Stable Update for Desktop

18 Augustus 2026 om 21:28

The Extended Stable channel has been updated to 150.0.7871.250 for Windows and Mac which will roll out over the coming days/weeks.

A full list of changes in this build is available in the log. Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.

Srinivas Sista
Google Chrome
  •  
❌