Lees weergave

5.5.0-beta.0

Changelog

Features

Bug fixes

Others

  •  

Asterisk Release 22.11.0

The Asterisk Development Team would like to announce
the release of asterisk-22.11.0.

The release artifacts are available for immediate download at
https://github.com/asterisk/asterisk/releases/tag/22.11.0
and
https://downloads.asterisk.org/pub/telephony/asterisk

Repository: https://github.com/asterisk/asterisk
Tag: 22.11.0

This release resolves issues reported by the community
and would have not been possible without your participation.

Thank You!

Change Log for Release asterisk-22.11.0

Links:

Summary:

  • Commits: 39
  • Commit Authors: 16
  • Issues Resolved: 28
  • Security Advisories Resolved: 0

  •  

Asterisk Release 23.5.0

The Asterisk Development Team would like to announce
the release of asterisk-23.5.0.

The release artifacts are available for immediate download at
https://github.com/asterisk/asterisk/releases/tag/23.5.0
and
https://downloads.asterisk.org/pub/telephony/asterisk

Repository: https://github.com/asterisk/asterisk
Tag: 23.5.0

This release resolves issues reported by the community
and would have not been possible without your participation.

Thank You!

Change Log for Release asterisk-23.5.0

Links:

Summary:

  • Commits: 39
  • Commit Authors: 16
  • Issues Resolved: 28
  • Security Advisories Resolved: 0

  •  

Asterisk Release 20.21.0

The Asterisk Development Team would like to announce
the release of asterisk-20.21.0.

The release artifacts are available for immediate download at
https://github.com/asterisk/asterisk/releases/tag/20.21.0
and
https://downloads.asterisk.org/pub/telephony/asterisk

Repository: https://github.com/asterisk/asterisk
Tag: 20.21.0

This release resolves issues reported by the community
and would have not been possible without your participation.

Thank You!

Change Log for Release asterisk-20.21.0

Links:

Summary:

  • Commits: 39
  • Commit Authors: 16
  • Issues Resolved: 28
  • Security Advisories Resolved: 0

  •  

Road Trip: Vehicle Configuration & Purchase Process Video Trailer

Last week, we shared a dedicated blog with you about the Vehicle Configuration & Purchase Process in our upcoming Road Trip module for American Truck Simulator. Today, we're happy to share a new video trailer showing you how it all works!


Our talented video producers have put together a trailer showcasing both the vehicle purchase process and how you can configure and customize your vehicle, which will work a little differently from what you may be used to with trucks in ATS. We hope you enjoy the video and that it gives you a clearer look at what to expect when Road Trip arrives further down the road.



If you're excited about Road Trip, make sure to add its DLCs, the Ford Car Pack and the RAM & Dodge Car Pack, to your Steam Wishlist!

Also, remember to follow us on X, Facebook, Instagram, Bluesky, and YouTube for all the latest Road Trip news and other American Truck Simulator updates, or sign up for our newsletter to stay informed. We'll see you on the road! 

  •  

Distribution Release: Butterbian 0.4.0

The DistroWatch news feed is brought to you by TUXEDO COMPUTERS. The Butterbian project has announced the availability of Butterbian 0.4.0, the latest stable release of the project's Debian-based Linux distribution with out-of-the-box support for the Btrfs filesystem and pre-configured Timeshift that takes incremental snapshots of the installed filesystem at regular intervals. The new version of the distribution updates....
  •  

Distribution Release: NawaOS 2.0

The DistroWatch news feed is brought to you by TUXEDO COMPUTERS. Ahmed Abdulla has announced the release of NawaOS 2.0, a new stable build of the project's Debian-based Linux distribution designed primarily for gamers. It includes Steam, Lutris, Wine and RetroArch pre-installed and configured. This new release comes with snapshots, a setup wizard, and various user-friendly gaming enhancements: "NawaOS....
  •  

NVIDIA Driver 616.56

Release Highlights:
Although GeForce Game Ready Drivers and NVIDIA Studio Drivers can be installed on supported notebook GPUs, the original equipment manufacturer (OEM) provides certified drivers for your specific notebook on their website. NVIDIA recommends that you check with your notebook OEM for recommended software updates for your notebook.

Game Ready for STAR WARS Zero Company™
This new Game Ready Driver provides the best gaming experience for the latest new games supporting DLSS and RTX technologies including STAR WARS Zero Company™, Resonance: A Plague Tale Legacy, and Hell Let Loose: Vietnam.

Fixed Gaming Bugs
  • DOOM: The Dark Ages & Indiana Jones and the Great Circle: Frame rate may exceed V-SYNC when DLSS Frame Generation 3x or higher is used [6061475]
  • Outer Worlds: Texture flicker may be observed while playing after updating to R595 and R610 drivers [6238668]

Fixed General Bugs
  • ASUS Armory Crate: GameVisual color profiles are not getting applied when using R590 drivers [5860581]
  • Chief Architect: 610.47 driver crash on Geforce RTX 4000 series cards [6226227]
  • Claude Desktop: Driver incorrectly detects application as a 3D app [6468260]
  • Resolves issue that some instances can cause a driver crash with 32-bit DirectX 12 apps [5725350]
  • Tycho Tracker: Unable to create individual OpenCL buffers greater than 2GB [6538978]

Learn more in our Game Ready Driver article here.

Game Ready Driver

  •  

uNmINeD 0.20.5-dev

New uNmINeD development snapshot is available for download!

Changes:

  • Right click menu items now work in isometric mode
  • Fixed isometric block rotation mismatches (mushroom blocks, logs)
  • Fixed isometric tile rendering failures (broken in 0.20.4)
  • Fixed isometric tile pixel alignment glitches (sometimes there was an one pixel gap between tiles)
  •  

v1.9.2 - Security Fix for DNS-Rebinding SSRF (GHSA-24w9-8r42-8jwm) & Spam-Free Push Notifications

1.9.2 (2026-08-26)

Thank you for your donations:

One-time

Monthly

Security

  • Calendar / Auth: Pin the resolved IP address at socket-connect time when fetching caller-supplied URLs (iCalendar subscriptions, JMAP login and TOTP token-exchange servers). The public-host check used to run before fetch() opened its socket, so an attacker who controlled DNS for a hostname could rebind it to loopback, RFC-1918 or cloud-metadata addresses between the check and the connect and read up to 10 MB of the internal response through the unauthenticated /api/fetch-ical endpoint. Redirect targets are now validated the same way (GHSA-24w9-8r42-8jwm, thanks @Tike00)

Features

  • Push: Re-sync existing push registrations in the background on app start, so registrations created before the delivery filter existed — or whose Junk mailbox id went stale — get repaired without re-enabling notifications

Fixes

  • Push: Stop sending notifications for spam — the push subscription now carries a JMAP emailPush delivery filter that excludes $junk and the Junk mailbox (needs a server advertising the emailPush capability, e.g. Stalwart ≥ 0.16.16; older servers keep the previous behaviour)

  •  

v4.3.12

Fixes

  • Applied authentication rate limits per real client behind reverse proxies and Cloudflare, preventing visitors from sharing one rate-limit bucket (#11515).
  • Reset a server's unreachable counter after a successful connection check, preventing stale failures and false unreachable alerts (#11417, closes #11416).
  • Corrected placeholder alignment in code editor fields (#11514, closes #11420).
  • Queued Cloud registration verification emails with retries, making delivery more reliable.

What's Changed

New Contributors

Full Changelog: v4.3.11...v4.3.12

  •  

UniFi Network Application 10.6.101

Overview

UniFi Network Application 10.6.101 adds Drift Inspector, Topology Spotlight, and expanded Safe Ops features, along with the improvements and bug fixes listed below.

 

Added Drift Inspector to Blueprints in Site Manager

  • Make local changes to sites using Blueprint orchestrations, with a clear view of configuration drift and an easy way to resolve it.


Added Topology Spotlight

  • Quickly highlight and filter selected devices for easier navigation and troubleshooting in large topologies.


Improved SafeOps features

  • Expanded Test & Confirm support to VPN and Management networks.
  • Added Nightly Channel AI Optimization with configurable radio selection and an improved optimization algorithm.


Improved Time Machine Experience

  • Added Time Machine for Radios to review radio usage metrics, configuration changes, and radio events from the past 24 hours.
  • Expanded Port Manager Time Machine to All Ports, making it easier to identify and troubleshoot problematic network segments.

Improvements

  • Added a flapping devices filter to Port Manager Time Machine for clients with frequent reconnections.
  • Added the Reduced Firewall State Timeouts profile for EFG, EF-Core, and UXG-Enterprise.
  • Added a confirmation prompt when updating all devices from the Devices filter side panel.
  • Added sorting to Network Lists and descriptions on hover.
  • Added column sorting to tables in Settings Overview.
  • Added an Allow Empty Password option for RADIUS MAC Authentication.
  • Added the ability to disable the LCM screen on meshed UX7 devices.
  • Added Sort by Topology to the Devices page.
  • Added a notice for unsupported devices in Test & Confirm settings.
  • Added a disabled port filter to Port Manager.
  • Added an Additional Labels option to Infrastructure Topology.
  • Added a warning in Topology when Sonos devices with mixed wired and wireless connections are detected.
  • Added validation to prevent OpenVPN Server and Site-to-Site VPNs from using the same UDP port.
  • Added a Spotlight selection option in Topology.
  • Added the ability to disable insecure OpenVPN compression.
  • Added Multicast Suppressor support.
  • Requires UAP 8.8 or newer.
  • Added a Lock Port to UniFi Device option to Port Manager.
  • Requires Switch firmware version 7.6 or newer.
  • Added support for adopting multiple U5G devices on the same site over LAN.
  • Added support for using Domain Network Lists in QoS Policies.
  • Added support for customizing WAN interfaces used for Automatic Speed Tests.
  • Added Bulk Update Management to the Devices page.
  • Improved Device Auto-Recovery stability.
  • Improved Data Plane Protection resiliency.
  • Improved Traffic Activity Statistics accuracy.
  • Improved the Observability section.
  • Improved the device revert experience by allowing easy reversion for all devices with the same Device model and version.
  • Improved DHCP Options validation.
  • Improved the Dynamic DNS settings user experience.
  • Improved RADIUS settings validation.
  • Improved Virtual Network management in Topology.
  • Improved the AV Manager user experience.
  • Improved Honeypot validation.
  • Improved the display of unstable links in Infrastructure Topology.
  • Improved network subnet validation against static route destinations.
  • Improved Port Profiles management in Port Manager.
  • Improved Port Manager by automatically opening Time Machine.
  • Improved the Device Update confirmation screen by showing the number of connected devices that might be interrupted.
  • Improved OpenVPN server configuration files by removing periodic TLS key renegotiation.
  • Requires UniFi OS 5.1 or newer
  • Improved VPN Server settings validation.
  • Improved application startup resiliency.
  • Improved the Port Forwarding table user experience.
  • Removed the Network Override option for WAN-adopted U5G devices.
  • Removed the STP Edge note from Port Manager when Auto STP Edge is disabled.
  • Separated the Reset Stats and Clear Last Seen Device actions in Port Manager.
  • Enabled DHCP Guarding by default on new networks.


Bugfixes

  • Fixed an issue where client devices with a configured Power Source could be automatically enrolled in Device Auto-Recovery.
  • Fixed an issue where the AP Stopped Mesh system log could be generated repeatedly after an AP switched to a wired uplink.
  • Fixed an issue where the High Traffic alarm incorrectly reported wireless client downloads as uploads.
  • Fixed an issue where SD-WAN Mesh VPN tunnels could remain after the configuration was removed.
  • Fixed an issue where the client count in the WiFi Broadcast overview was incorrect when MLO clients were connected.
  • Fixed an issue where filter counters could flicker on the Connectivity page in rare cases.
  • Fixed an issue where the hostname was not set correctly for a UX7 connected via mesh.
  • Fixed an issue where a custom APN could be lost after moving a SIM between slots on a U5G.
  • Fixed an issue where the UX7 did not display connected wireless clients in the Devices list.
  • Fixed a rare issue where opening Client Observability could impact system stability.
  • Fixed an issue where DAS/DAC (CoA) was unavailable when using Open security with RADIUS MAC Authentication.
  • Fixed an issue where MC-LAG configurations could be lost after restoring a backup.
  • Fixed an issue where the Connectivity page was missing some roaming events.
  • Fixed a rare issue where adopting an LTE device could cause a gateway configuration error.

Additional information



 

UniFi OS Server


Going forward, we recommend users upgrade to UniFi OS Server for all self-hosted deployments. It provides the full UniFi OS Platform experience, ensuring you receive the latest features, improvements, and integrations.



UniFi Network Native Application for UniFi OS

Compatible with UDM, UDR, UDR7, UDR 5G Max, Express, Express 7, and UCG models (Ultra, Max, Fiber, and Industrial) on UniFi OS 3.1.6 or later. UDM-Pro, UDM-SE, and UDW have been using it since UniFi OS 5.1.5.

  • The UniFi OS update utilizes the application version compatible with your console.
  • The manual update process via SSH requires a compatible package. Incompatible packages will be rejected on installation.
  • Older UniFi OS versions (prior to UniFi OS 3.1.6) on the UDM and UDR continue to utilize the standard UniFi Network Application for UniFi OS.

 

 Checksums

c8c6398042ebc33a683c96850aa24b44 | UniFi-installer.exe
3128c428fa31641367b85c5c1b9b73a7 | UniFi-Network-Server.dmg
fe450c8e838c4fc3c93edaab901585f1 | UniFi.unix.zip
338929b19c8a14cb2f0db93906c1ad52 | unifi_sysvinit_all.deb
353b46578d3c008eb05e8eb9966d6be2 | unifi-uos_sysvinit.deb
4fd0700d012cf05323bea1684f409508 | unifi-native_sysvinit.deb
601df32736f41e40a80a3e472450a3e1 | unifi_sh_api


------------------------------------------------------------------------------------------------------------------------


75d6fda3b5b11722bda1e1f1680e7513e95de0862fa441ac30fb1b017fecf5ec | UniFi-installer.exe
62aae907b989a34392f82818ce339829b441d59d40643e7d3c8c78b8e3d08fbb | UniFi-Network-Server.dmg
18db9cbe4572de443df204ecf8ff30a906579058cc8d67dfba990ad163881477 | UniFi.unix.zip
b5ab809c2680b7ec22106ef19c7942f1fa343338c3eed1829303d95b2ce4fdd7 | unifi_sysvinit_all.deb
0e93972c1bc02aa2352812d84fa15cbb7433b6ec753308e706bd65068a2eda8d | unifi-uos_sysvinit.deb
00c8f461f576a03a6124abec433d2a71fcb854a6f07bebfa77f32cd32a9460e7 | unifi-native_sysvinit.deb
1791685039ea795970bcc7a61eec854058e3e6fc13c52770e31e20f3beb622eb | unifi_sh_api
  •  

Early Stable Update for Desktop

The Stable channel has been updated to 153.0.8010.12/.13 for Windows and Mac as part of our early stable release to a small percentage of users. A full list of changes in this build is available in the log.

You can find more details about early Stable releases here.

Interested in switching release channels?  Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.


Srinivas Sista

Google Chrome

  •  

v1.9.1 - Fix Next 16.3 Navigation Redirect Loop & DAVx5 Calendar Sync

1.9.1 (2026-08-26)

Thank you for your donations:

One-time

Monthly

Fixes

  • Navigation: Forward every request header through the proxy — Next 16.3's RSC header check rejected the stripped router headers and sent navigations into a 307 redirect loop (#919)
  • Calendar: Stop emitting RSCALE=GREGORIAN;SKIP=OMIT on plain Gregorian recurrence rules — DAVx5 rejected them as invalid and Android sync broke (#805, thanks @hildebrandttk)

  •  

Nevada Rework Project: Meet the Team

Today, we’re excited to introduce you to some of the talented team members behind the upcoming Nevada Rework for American Truck Simulator. This project brings a fresh look to one of the game’s original states, with updated roads, cities, landscapes, and landmarks that better reflect our current standards.

In this Meet the Team episode, you’ll hear directly from the developers who have been working on different parts of Nevada and learn more about their experiences, favorite locations, and what they’re most looking forward to players discovering. So, let’s take a closer look at the people helping bring the Silver State back to life!

Ella - Senior Map Designer

I’ve been at SCS for close to 7 years, and in that time I’ve worked on many projects, starting my journey with the Utah DLC in 2019. From there, I moved on to work on large cities across several states, such as El Paso, Texas; San Diego, California; and Albuquerque, New Mexico.

As our team’s road specialist, I oversee Nevada’s road layout and also do work on some of the truck stops there, which are critical for our gameplay by providing players an opportunity to refuel and rest. Besides that, I’m working on the city of Phoenix, Arizona, which will be included as another part of our Rework project.

I’m looking forward to watching players explore the newly added locations and seeing their reactions as well as getting their feedback, which is always appreciated. I love creating maps so many people enjoy driving in; that always feels very rewarding on its own. 

Johny - Senior Map Designer

I’ve been at SCS for six years. I started out working on sections of Texas and Montana before moving fully into Rework. I’ve been part of the rework team since the very beginning.

Over the years, I’ve worked on both roads and cities, including San Jose, Santa Cruz, El Centro, and Grand Canyon. Most recently, for the Nevada Rework, I’ve been working on the roads around Panaca and Las Vegas, as well as Panaca itself and the northern part of Las Vegas.

I love working on epic scenery, which is why I really enjoyed working on the Grand Canyon, and I’m having just as much fun working on Las Vegas now. I think Nevada will now meet our current standards, and players can look forward to a faithful recreation of the real-life locations.

Pavel - Senior Map Designer

I've been part of SCS for almost four years now. I started my journey with the third phase of the California Rework, where Fresno was the first city I had the opportunity to work on. Since then, I've remained part of the Rework team, working on cities across different projects. As part of the Nevada Rework, I'm currently working on Reno and Fallon.

Reno is being completely rebuilt from the ground up, and one of my main goals was to capture the atmosphere and scale of the city. I put a lot of focus on the city's layout, character and recognizable landmarks, while also trying to keep some of the feeling of the original city that players might remember. The area will also feature reworked sections of I-80, which I'm really looking forward to seeing players experience. 

Fallon is a much smaller city, but its location gives it a character of its own. Surrounded by the vast Nevada desert, it feels almost like a small oasis in the middle of nowhere, with the greenery and farmland around the city standing out against the otherwise dry landscape. There is definitely a lot for players to look forward to, and I hope they'll enjoy exploring these areas as much as I enjoyed working on them.

Tom - Map Designer

I'm doing mainly landscape, and I'm in the rework team since California's 2nd phase; my favourite tasks were forests with mountains and lakes, which I haven't seen in a while.

Luckily, Nevada offers dry mountains and hills providing interesting tall horizons which diversify the barren desert.

Nevada is also unique for long straight roads compared to other DLCs. If you enjoy driving into the distant horizon, you'll most likely enjoy it.

Roman - Map Designer

This October marks my fourth year at SCS. In my time on the ATS rework team, I had the chance to work on multiple phases of the California rework, the Route 66 rework project, and now Nevada. With each rework, I slowly figured out that I enjoy making detailed cities more than anything else, though the cities have never been as large or famous as the one I have been working on now.

Las Vegas has been quite a challenge compared to my previous cities, but it also gives many opportunities for fun detail work and making the city feel alive. I hope that the NEW Vegas is fun to explore for new players and even more fun to re-explore for returning trucking veterans.

Margo - Map Designer

Hi there! It’s been a ride here in the Rework team since I joined the company in 2022. Every year, a new project brings us something new to work on. I had the pleasure of working on the California rework, parts of Arizona, and now Nevada as well. Reworking Nevada brought me something I already knew and made me rethink my working approach, as my perspective changed a lot through the years.

Creating for me always comes with a deeper meaning to it. I don’t want my work to be just purely mechanical and soulless; I like hiding fun details in the ordinary. If spotting it makes someone smile or catches their attention - it’s worth it.

We really should be cultivating our curiosity and wonder more in our daily lives. So if you are already wondering about the brand new Nevada, that’s a good starting point. There are many cool places to see and some nice UFO references to spot!

Filip - Map Designer

Hello everybody! My map designer journey began during the fourth phase of the California rework, where I worked on smaller tasks suited for a rookie like me. On the Route 66 rework project, I was responsible for the design of I-191 and Page. I got to experience a bit of everything: a diverse road with settlements, scenic views, beautiful landscapes, and a challenging hilly city.

The experience I gained, I can now utilize in a brand new look of Nevada, where I am working on Carson City, its surroundings, and a small surprise.

I hope the work of our team will bring a fresh, up-to-date look to Nevada and that players will be able to rediscover this awesome state for a second time!

Mykyta - Map Designer

I have been working at SCS Software for two years, and during that time I have worked on projects such as Route 66 around Tucumcari. 

As part of the Nevada Rework, I am currently working on the towns of Elko and Carlin and their surrounding areas. 

Players can look forward to driving through the Carlin Tunnel, and if they pay close attention along the way, they may also discover some beautiful and interesting places in the surrounding landscape. 

Jakub - Map Designer

I have been in SCS for more than a year. I started with reworking the northern part of Arizona and New Mexico. Now, reworking Nevada is another dream project of mine.

As a big fan of clean, big open landscapes and amazing mountains, rocks, and other unique hills, I enjoyed every road I've been working on, and now I am happy that Nevada looks like Nevada.

Rob - Junior Map Designer

Hi everyone, I’m Rob, and I’ve been with SCS for over a year now. The Nevada Rework is my first major project. Before that, I mainly worked on smaller projects in Arizona.

My part of the map is located in northern Nevada, where I’ve been working to bring the area as close to reality as possible and capture the atmosphere of sun-baked roads stretching through the endless desert. Players can look forward not only to the rugged, arid landscape, but also to beautiful and highly detailed cities.

I’m happy that we can give players a fresh take on familiar content and offer them the chance to experience Nevada in a slightly different and completely new way.

Filip - Junior Map Designer

Hi, I’ve only been in SCS for four months, but I already feel right at home here. Nevada is a beautiful state, and I’ve really enjoyed exploring it.

I was tasked with completing the road from Las Vegas to Panaca. It was a privilege to work on the surrounding mountain ranges and finish the work started by my colleague Johny. There is also a Visitor Center near Panaca, and I think I managed to capture it in all its beauty. So, I’d definitely recommend that players take a little detour from the road and explore the area around it.

Samuel - Junior Map Designer

Hi, my name is Sam, and I recently passed the five-month mark at SCS Software. Having grown up playing SCS games, being able to contribute to their development is a dream come true for me.

On this project, I worked on shorter roads in the western part of Nevada. Hopefully, I managed to capture the authentic feel of the landscape, biomes, and unique character of the area, and you'll enjoy driving through them! I’m really looking forward to showing you even more of my work in future DLCs.

That concludes today’s Meet the Team! We’d like to thank everyone featured in this blog for taking the time to share a little about themselves and their work on the Nevada Rework.

We always enjoy giving our community a glimpse behind the scenes and highlighting the talented people who help bring our virtual worlds to life. We hope you enjoyed learning more about the team and the passion they’re putting into giving Nevada a fresh new look.

As development continues, we look forward to sharing more from the Nevada Rework with you. Be sure to follow us on X/Twitter, Instagram, Facebook, Bluesky, YouTube, and TikTok, or subscribe to our newsletter, so you never miss any updates. Until next time, we will see you on the road!

  •  

Development Release: Haiku R1 Beta 6

The DistroWatch news feed is brought to you by TUXEDO COMPUTERS. The Haiku project has released a new development snapshot of the lightweight, single-user operating system. Haiku R1 Beta 6 introduces support for multiple web browsers and features a port of the NetBSD Virtual Machine Manager (NVMM), which provides hardware virtualization on x86_64 machines. "A few months after the....
  •  

Anonymous and open to all: The Home Assistant survey dataset

Our why as an organization is clear: to fight for privacy, choice, and sustainability for smart homes, and for every person who lives in one. But who does live in them?

In December 2024, we launched the first Home Assistant survey to find out. Our goal was simple: to make Home Assistant more inclusive and approachable by listening directly to the diverse community of people who use it.

In the spirit of building in the open, today we’re thrilled to announce the anonymized results of that survey are now freely available. In this post, we’ll run you through what the survey covered, why and how we’re publishing this data, what the data is not (read: identifiable), how we’re using this information to improve what we do, and opportunities for further understanding and research.

  •  

FileZilla Client 3.71.1 released

Bugfixes and minor changes:

  • macOS: Work around a bug in macOS 27 where setting the locale to non-English triggers crashes in AppKit
  • SFTP: Improved heuristic when keyboard-interactive requests are treated as a simple password prompt on servers not offering the password authentication method
  •  

Distribution Release: Armbian 26.8.3

The DistroWatch news feed is brought to you by TUXEDO COMPUTERS. The Armbian distribution is designed for ARM development boards and a range of other machines. The project's latest release, version 26.8.3, introduces a few key change, including a new system installer. "Most releases are a long list of small improvements. This one had three larger pieces landing at....
  •  

v5.52.2

5.52.2 (2026-08-26)

✨ New Media Library (opt-in beta)

A complete revamped Media Library UI is available behind a feature flag. Set future.betaMediaLibrary: true in config/features and restart your app; it replaces the legacy Media Library when enabled (disabled by default). More info in docs and the Notion Page

Feedback while it's behind the flag is very welcome. Enjoy!

Image details

🔥 Bug fix

  • make drag and drop more fluently in configuation view fix#23161 (#26320, #23161)
  • admin: out of sort memory when listing audit logs on mysql (#27410)
  • admin: send credentials on fetch client requests (#27413)
  • admin: keep api token permissions on localized content types at boot (#27420)
  • admin: honour redirectTo when the auth page redirects an authenticated user (#27213)
  • admin: slow startup with many roles due to redundant permission … (#27438)
  • content-manager: draft status filter with i18n sibling locale published (#26835)
  • content-manager: reject MCP relation writes combining set with connect or disconnect (#27423)
  • content-manager: out of sort memory when listing history versions on mysql (#27394)
  • core: Access token rotation fails with asymmetric JWT algorithms (#27201)
  • core: serialize JSON columns before INSERT in discard-drafts migration (#25927)
  • core/strapi: local plugins duplicate the admin module graph and exhaust build memory (#27311)
  • database: relation reorder saves the wrong position (#27444)
  • i18n: correct broken placeholders in pt-BR translations (#27257, #27383)
  • permissions: surface clear error for unsupported RBAC condition operators (#27355)
  • plugins: admin build fails to resolve @strapi/admin under isolated node_modules (#27337)
  • upload: translate server error codes in the new media library (#27345)
  • upload: sizeLimit is not enforced when replacing a file (#27414)
  • upload: move replace media to the drawer footer, add tooltips (#27425)
  • upload: list queued files in the upload progress dialog (#27416)
  • upload: merge a second drop into the running upload batch (#27415)

⚙️ Chore

  • replace lodash forEach with native Object.entries/values (#27409)
  • add worktree bootstrap command (#27426)
  • deps: upgrade memfs to 4.68.1 in @strapi/upgrade (#27406)
  • deps: migrate first-party zod to 4.4.3 (#27428)

💅 Enhancement

  • data-transfer: clarify partial transfer stage scope (#27322)
  • database: log internal migrations at info level (#27324)
  • database: add migration progress heartbeats (#27325)

🚨 Security

  • graphql: warn about unbounded operation limits (#27390)
  • upload: deny svg in generated project defaults (#27360)

⚠️ Changes to be aware of

New projects block SVG uploads by default

Apps created with create-strapi-app now reject SVG files in the Media Library by default, because SVG can include active browser content. Existing projects are unchanged; if you need SVG in a new project, allow image/svg+xml in the generated upload security config.
(#27360)

❤️ Thank You

  •  

12.0 RC6

🚀 Jellyfin Server 12.0 RC6

We are pleased to announce the sixth release candidate preview release of Jellyfin 12.0!

This is a preview release, intended for those interested in testing 12.0 before its final public release. We welcome testers to help find as many bugs as we can before the final release.

As always, please ensure you stop your Jellyfin server and take a full backup before upgrading!

A note about versioning

Starting with this release, we are dropping the preceding 10. from our versioning. Thus, 10.11.x -> [10.]12.x = 12.x. The reason is simple: at this point in the project, we don't envision a hard break in the API like we planned way back in the early days, and this version scheme was causing a lot of confusion amongst users about what a "major" release was. For more information, please see the RC1 release notes.

What's new?

The main goal of this release has been performance. 10.11.0 dropped a major backend rewrite, and while it was broadly functional, it had a lot of rough edges. This release seeks to polish out most of those rough edges and bring better performance to all users.

There are many other small fixes, improvements, changes, and translations. See our draft release notes here or below for the full list of pull requests. You can also view the Web side changelog here.

Note: You must be on Jellyfin 10.10.7+ or 10.11.x (ideally, 10.11.11) before upgrading! If you are not, the upgrade will fail. Ensure you upgrade to one of these versions first!

Note: The initial load of Jellyfin 12.x will run a few migrations and will take several minutes. Please be patient and do not interrupt the process. You can leverage the (newly improved!) startup UI on your local network to see specific progress, or off-network to see general progress, by visiting the server URL in your web browser during startup.

Note: If you install the RC, you should disable all external plugins and reinstall using the unstable plugin repository, or plugins may fail to load and cause unintended side effects.

Installing

This preview release is distributed in all our traditional forms, though not automatically via our Apt repository or latest tag.

  • For all non-Docker environments, you can find the files for manual download in our repository by selecting "Stable Preview" for your OS.
  • For Docker, you can pull the 12.0-rc6 or preview tags.

What's Changed (since v12.0-rc5)

New Contributors

Full Changelog: v12.0-rc5...v12.0-rc6

  •  

12.0 RC6

🚀 Jellyfin Web 12.0 RC6

We are pleased to announce the sixth release candidate preview release of Jellyfin 12.0!

This is a preview release, intended for those interested in testing 12.0 before it's final public release. We welcome testers to help find as many bugs as we can before the final release.

As always, please ensure you stop your Jellyfin server and take a full backup before upgrading!

A note about versioning

Starting with this release, we are dropping the preceding 10. from our versioning. Thus, 10.11.x -> [10.]12.x = 12.x. The reason is simple: at this point in the project, we don't envision a hard break in the API like we planned way back in the early days, and this version scheme was causing a lot of confusion amongst users about what a "major" release was. For more information, please see the RC1 release notes.

What's new?

The main goal of this release has been performance. 10.11.0 dropped a major backend rewrite, and while it was broadly functional, it had a lot of rough edges. This release seeks to polish out most of those rough edges and bring better performance to all users.

There are many other small fixes, improvements, changes, and translations. See our draft release notes here or below for the full list of pull requests. You can also view the Server side changelog here.

Note: You must be on Jellyfin 10.10.7+ or 10.11.x (ideally, 10.11.11) before upgrading! If you are not, the upgrade will fail. Ensure you upgrade to one of these versions first!

Note: The initial load of Jellyfin 12.x will run a few migrations and will take several minutes. Please be patient and do not interrupt the process. You can leverage the (newly improved!) startup UI on your local network to see specific progress, or off-network to see general progress, by visiting the server URL in your web browser during startup.

Note: If you install the RC, you should disable all external plugins and reinstall using the unstable plugin repository, or plugins may fail to load and cause unintended side effects.

Installing

This preview release is distributed in all our traditional forms, though not automatically via our Apt repository or latest tag.

  • For all non-Docker environments, you can find the files for manual download in our repository by selecting "Stable Preview" for your OS.
  • For Docker, you can pull the 12.0-rc6 or preview tags.

What's Changed (since v12.0-rc5)

Full Changelog: v12.0-rc5...v12.0-rc6

  •  

uNmINeD 0.20.4-dev

New uNmINeD development snapshot is available for download!

Changes:

  • Optimizations for isometric mode (more speed, reduced memory usage)
  • Isometric mode is now available from zoom 1:1 to 16:1
  • Fixed KeyNotFoundException when rendering zoom-out tiles for web
  •  

v4.3.11

Features

  • Added asynchronous DNS validation for application and service domains.
  • Added one-click service templates for HashiCorp Vault and Obsidian LiveSync CouchDB.

Fixes

  • Restored proxy connections to project networks after host reboots (#11476, fixes #11436).
  • Applied custom Docker options when applications used custom container names, honored selected rollback tags, and respected Compose stop grace periods (#11479, #11480, #11498).
  • Restored custom-format PostgreSQL backups with pg_restore (#11481, fixes #11459).
  • Removed persistent volumes when deleting application previews (#11455, fixes #11441).
  • Made Docker cleanup safe to retry and prevented missing resources from failing deletion (#11463).
  • Fixed registry pushes by updating the helper image's Docker CLI, Compose, and Buildx versions (#11461, fixes #11437).
  • Fixed service log lookup when Docker label values contained commas (#11477, fixes #11454).
  • Allowed system-wide GitHub Apps to work across teams and accepted Coolify CUIDs when updating their private keys through the API (#11453, #11468).
  • Allowed teams with unused private keys or system-wide Git sources to be deleted without removing shared sources (#11499, #11500, fixes #11494).
  • Restored clickable commit links in deployment logs (#11495, fixes #11482).
  • Cleared stale Traefik branch-upgrade warnings after the suggested branch was applied (#11496, fixes #11490).
  • Kept private-key edit dialogs working after multiple keys were deleted (#11497, fixes #11487).
  • Fixed terminal container selection when identical container names existed on different servers.
  • Refreshed service configuration after required environment variables changed.
  • Redacted dotted GitHub tokens from exported logs and prevented wide tables from overflowing their containers.

Improvements

  • Showed a toast with retry guidance when infrastructure-related Livewire requests failed.
  • Distinguished proxy restarts from proxy updates in server status indicators.
  • Made stuck-resource cleanup scalable, scheduled it automatically, and made resource deletion metadata updates atomic.

New Contributors

Full Changelog: v4.3.10...v4.3.11

  •  

Stable Channel Update for Desktop

The Chrome team is delighted to announce the promotion of Chrome 152 to the stable channel for Windows, Mac and Linux. This will roll out over the coming days/weeks.

Chrome 152.0.7977.64 (Linux) 152.0.7977.64/.65 Windows/Mac contains a number of fixes and improvements -- a list of changes is available in the log. Watch out for upcoming Chrome and Chromium blog posts about new features and big efforts delivered in 152.


Security Fixes and Rewards

Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.

This update includes 327 security fixes. Please see the Chrome Security Page for more information.


[$25,000][496807874] Critical CVE-2026-79282: Use after free in ANGLE. Reported by Goodluck on 2026-03-27

[N/A][516427761] Critical CVE-2026-79290: Use after free in Aura. Reported by Google on 2026-05-25

[N/A][516764384] Critical CVE-2026-79054: Use after free in Chromecast. Reported by Google on 2026-05-26

[N/A][516777082] Critical CVE-2026-79121: Improper input validation in Chromecast. Reported by Google on 2026-05-26

[N/A][516988476] Critical CVE-2026-79224: Use after free in Chromecast. Reported by Google on 2026-05-27

[N/A][517518019] Critical CVE-2026-79052: Use after free in Aura. Reported by Google on 2026-05-28

[N/A][518006007] Critical CVE-2026-79150: Use after free in Views. Reported by Google on 2026-05-29

[N/A][522082472] Critical CVE-2026-78935: Use of uninitialized variable in Mobile. Reported by Google on 2026-06-10

[N/A][523704817] Critical CVE-2026-79012: Use after free in Safebrowsing. Reported by Google on 2026-06-13

[N/A][532921800] Critical CVE-2026-79200: Use after free in Aura. Reported by Google on 2026-07-09

[$1,000][532617619] High CVE-2026-78989: Out of bounds read in ANGLE. Reported by Đặng Thế Tuyến on 2026-07-09

[$500][508638064] High CVE-2026-79069: Memory corruption in Tint. Reported by andryskowski.michal on 2026-05-01

[N/A][498885920] High CVE-2026-79175: Type confusion in Accessibility. Reported by Google on 2026-04-02

[N/A][500311587] High CVE-2026-79218: Incorrect authorization in Sandbox. Reported by Google on 2026-04-07

[N/A][501892500] High CVE-2026-79195: Use after free in Script. Reported by Google on 2026-04-12

[N/A][513261751] High CVE-2026-78939: Use after free in Chromecast. Reported by Google on 2026-05-14

[N/A][515470739] High CVE-2026-79194: Use after free in Chromoting. Reported by Google on 2026-05-21

[N/A][515473074] High CVE-2026-79247: Use after free in Chromoting. Reported by Google on 2026-05-21

[N/A][516947491] High CVE-2026-79219: Use after free in Bluetooth. Reported by Google on 2026-05-27

[N/A][517515945] High CVE-2026-79047: Use after free in Views. Reported by Google on 2026-05-28

[N/A][517519352] High CVE-2026-79292: Integer overflow in Chromecast. Reported by Google on 2026-05-28

[N/A][517527943] High CVE-2026-78986: Uninitialized resource in GPU. Reported by Google on 2026-05-28

[N/A][517548647] High CVE-2026-79039: Use after free in Mobile. Reported by Google on 2026-05-28

[N/A][517550232] High CVE-2026-78934: Race condition in ReadAloud. Reported by Google on 2026-05-28

[N/A][517736936] High CVE-2026-79011: UI misrepresentation in Browser. Reported by Google on 2026-05-29

[N/A][517742721] High CVE-2026-78911: Incorrect authorization in USB. Reported by Google on 2026-05-29

[N/A][517959443] High CVE-2026-79257: Use after free in Views. Reported by Google on 2026-05-29

[N/A][521285077] High CVE-2026-79202: Use after free in Chromecast. Reported by Google on 2026-06-08

[N/A][521502218] High CVE-2026-79212: Missing authorization in Passwords. Reported by Google on 2026-06-08

[N/A][521942358] High CVE-2026-79183: Use after free in Accessibility. Reported by Google on 2026-06-09

[N/A][522294538] High CVE-2026-79155: Race condition in FileSystem. Reported by Google on 2026-06-10

[N/A][523095011] High CVE-2026-79093: Incorrect authorization in Paint. Reported by Google on 2026-06-12

[N/A][523266585] High CVE-2026-79019: Out of bounds write in ANGLE. Reported by Google on 2026-06-12

[N/A][523296105] High CVE-2026-79187: Use after free in WebRTC. Reported by Google on 2026-06-12

[N/A][523714535] High CVE-2026-79288: Improper input validation in Autofill. Reported by Google on 2026-06-14

[N/A][523717796] High CVE-2026-79130: Buffer overflow in ANGLE. Reported by Google on 2026-06-14

[N/A][523723064] High CVE-2026-78965: Uninitialized resource in ANGLE. Reported by Google on 2026-06-14

[N/A][523738212] High CVE-2026-79117: Race condition in WebAppInstalls. Reported by Google on 2026-06-14

[N/A][524698525] High CVE-2026-79082: Incorrect authorization in Transactions Platform. Reported by Google on 2026-06-16

[N/A][525683797] High CVE-2026-79111: Improper input validation in Dawn. Reported by Google on 2026-06-19

[N/A][528397177] High CVE-2026-79072: Improper state validation in Performance. Reported by Google on 2026-06-27

[N/A][529509587] High CVE-2026-79142: Buffer overflow in ANGLE. Reported by Google on 2026-06-30

[N/A][529991907] High CVE-2026-78948: Buffer overflow in WebGL. Reported by Google on 2026-07-01

[N/A][532904047] High CVE-2026-78908: Information leak in Canvas. Reported by Google on 2026-07-09

[N/A][532914190] High CVE-2026-78895: Information leak in Paint. Reported by Google on 2026-07-09

[N/A][532988552] High CVE-2026-79043: Out of bounds write in ANGLE. Reported by Google on 2026-07-09

[N/A][534468209] High CVE-2026-79235: Use after free in WebGL. Reported by Google on 2026-07-13

[N/A][534591074] High CVE-2026-79232: Use after free in Aura. Reported by Google on 2026-07-14

[N/A][535379043] High CVE-2026-79118: Uninitialized resource in ANGLE. Reported by Google on 2026-07-16

[TBD][535876894] High CVE-2026-79174: Incorrect authorization in Extensions. Reported by 章鱼哥@aipyaipy.com on 2026-07-17

[N/A][536428615] High CVE-2026-78900: Improper input validation in Media. Reported by Google on 2026-07-19

[N/A][536444272] High CVE-2026-79188: Out of bounds write in ANGLE. Reported by Google on 2026-07-19

[N/A][536505721] High CVE-2026-79189: Out of bounds write in ANGLE. Reported by Google on 2026-07-19

[N/A][536531630] High CVE-2026-79048: Out of bounds write in ANGLE. Reported by Google on 2026-07-19

[N/A][536532605] High CVE-2026-79240: Out of bounds write in ANGLE. Reported by Google on 2026-07-19

[N/A][536568319] High CVE-2026-79014: Race condition in Autofill. Reported by Google on 2026-07-19

[N/A][536606137] High CVE-2026-79198: Use after free in Platform. Reported by Google on 2026-07-19

[N/A][536626343] High CVE-2026-79131: Out of bounds write in ANGLE. Reported by Google on 2026-07-19

[N/A][536636648] High CVE-2026-79149: Use after free in ANGLE. Reported by Google on 2026-07-19

[N/A][536659904] High CVE-2026-79275: Use after free in ANGLE. Reported by Google on 2026-07-20

[N/A][536681676] High CVE-2026-79138: Out of bounds write in ANGLE. Reported by Google on 2026-07-20

[N/A][537109028] High CVE-2026-79026: Use after free in Extensions. Reported by Google on 2026-07-21

[TBD][537233963] High CVE-2026-79027: Use after free in WebRTC. Reported by Mozilla on 2026-07-21

[N/A][537835609] High CVE-2026-78904: Type confusion in ANGLE. Reported by Google on 2026-07-22

[TBD][540430406] High CVE-2026-78899: Use after free in V8. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern) on 2026-07-29

[N/A][540870921] High CVE-2026-78954: Incorrect authorization in Extensions. Reported by Google on 2026-07-30

[TBD][543707066] High CVE-2026-79274: Information leak in GPU. Reported by weihengqiuu on 2026-08-07

[TBD][545767601] High CVE-2026-78938: Type confusion in V8. Reported by Zhenpeng (Leo) Lin at depthfirst on 2026-08-12

[TBD][545820931] High CVE-2026-78952: Out of bounds write in Crashpad. Reported by Brendan Dolan-Gavitt, XBOW on 2026-08-13

[TBD][546670199] High CVE-2026-79236: Type confusion in V8. Reported by Zhenpeng (Leo) Lin on 2026-08-14

[TBD][548340637] High CVE-2026-79078: Use after free in FedCM. Reported by m0omo0d on 2026-08-18

[$8,000][495021566] Medium CVE-2026-79209: Type confusion in Animation. Reported by ochko on 2026-03-22

[$2,000][40057398] Medium CVE-2026-79030: Observable discrepancy in Autofill. Reported by Young Min Kim (@ylemkimon), CompSec Lab at Seoul National

University on 2021-09-25

[$1,000][536913431] Medium CVE-2026-79216: Buffer overflow in Blink. Reported by Found by XBOW and triaged by Andrés Luksenberg on 2026-07-20

[N/A][495579602] Medium CVE-2026-79007: Uninitialized resource in GPU. Reported by Google on 2026-03-24

[N/A][495998981] Medium CVE-2026-78893: Information leak in QUIC. Reported by Google on 2026-03-25

[N/A][496195129] Medium CVE-2026-79222: Incorrect authorization in CustomTabs. Reported by Google on 2026-03-25

[N/A][496292729] Medium CVE-2026-79071: Race condition in GPU. Reported by Google on 2026-03-25

[N/A][496395158] Medium CVE-2026-79076: Improper input validation in Sync. Reported by Google on 2026-03-26

[N/A][496401361] Medium CVE-2026-79088: Incorrect authorization in FileSystem. Reported by Google on 2026-03-26

[N/A][497017869] Medium CVE-2026-79104: Missing authorization in Sensor. Reported by Google on 2026-03-27

[N/A][497095313] Medium CVE-2026-79044: Missing authorization in WebAppInstalls. Reported by Google on 2026-03-28

[N/A][497205529] Medium CVE-2026-78958: Uninitialized resource in Skia. Reported by Google on 2026-03-28

[N/A][497269030] Medium CVE-2026-78961: Incorrect authorization in Core. Reported by Google on 2026-03-28

[N/A][497338168] Medium CVE-2026-79262: Incorrect authorization in Network. Reported by Google on 2026-03-29

[N/A][497456156] Medium CVE-2026-79106: Improper input validation in Input. Reported by Google on 2026-03-29

[N/A][497538341] Medium CVE-2026-79176: UI misrepresentation in Extensions. Reported by Google on 2026-03-29

[N/A][497637694] Medium CVE-2026-78966: Externally controlled reference in QUIC. Reported by Google on 2026-03-30

[N/A][497646947] Medium CVE-2026-79186: Incorrect authorization in Network. Reported by Google on 2026-03-30

[N/A][497839983] Medium CVE-2026-79267: Race condition in Workers. Reported by Google on 2026-03-30

[N/A][497854976] Medium CVE-2026-79016: Observable discrepancy in SVG. Reported by Google on 2026-03-30

[N/A][497869284] Medium CVE-2026-79010: Operation on a resource after expiration or release in Network. Reported by Google on 2026-03-30

[N/A][497940451] Medium CVE-2026-79286: Missing authorization in CustomTabs. Reported by Google on 2026-03-30

[N/A][497948894] Medium CVE-2026-78945: Use after free in Views. Reported by Google on 2026-03-30

[N/A][497957278] Medium CVE-2026-78999: Improper privilege management in Navigation. Reported by Google on 2026-03-30

[N/A][498327743] Medium CVE-2026-78941: Information leak in Core. Reported by Google on 2026-03-31

[N/A][498328139] Medium CVE-2026-79032: Improper input validation in Network. Reported by Google on 2026-03-31

[N/A][498367544] Medium CVE-2026-79109: Improper input validation in Printing. Reported by Google on 2026-04-01

[N/A][499007248] Medium CVE-2026-79256: Externally controlled reference in WebView. Reported by Google on 2026-04-02

[N/A][499068536] Medium CVE-2026-79237: Incorrect authorization in Navigation. Reported by Google on 2026-04-02

[N/A][499423269] Medium CVE-2026-78898: Incorrect authorization in Downloads. Reported by Google on 2026-04-04

[N/A][500038021] Medium CVE-2026-78985: Incorrect reference resolution in FileSystem. Reported by Google on 2026-04-06

[N/A][500492844] Medium CVE-2026-79028: Observable discrepancy in Network. Reported by Google on 2026-04-08

[N/A][501331457] Medium CVE-2026-79210: Use after free in Audio. Reported by Google on 2026-04-10

[N/A][501437087] Medium CVE-2026-79046: Race condition in Permissions. Reported by Google on 2026-04-10

[N/A][501572758] Medium CVE-2026-79129: Use after free in Sessions. Reported by Google on 2026-04-11

[N/A][501590191] Medium CVE-2026-78937: Use after free in Search. Reported by Google on 2026-04-11

[N/A][501594511] Medium CVE-2026-78987: Information leak in Canvas. Reported by Google on 2026-04-11

[N/A][501604761] Medium CVE-2026-78990: Use after free in Compositing. Reported by Google on 2026-04-11

[N/A][501637242] Medium CVE-2026-78909: Use after free in Views. Reported by Google on 2026-04-11

[N/A][501661601] Medium CVE-2026-79271: Information leak in DOM. Reported by Google on 2026-04-11

[N/A][501759192] Medium CVE-2026-79144: Information leak in Skia. Reported by Google on 2026-04-11

[N/A][501799770] Medium CVE-2026-79065: Improper input validation in Network. Reported by Google on 2026-04-12

[N/A][502082953] Medium CVE-2026-79192: Improper input validation in Variations. Reported by Google on 2026-04-13

[N/A][502101200] Medium CVE-2026-79140: Use after free in Views. Reported by Google on 2026-04-13

[N/A][502109333] Medium CVE-2026-79128: Use after free in Views. Reported by Google on 2026-04-13

[N/A][502139081] Medium CVE-2026-78942: Incorrect reference resolution in Loader. Reported by Google on 2026-04-13

[N/A][502232151] Medium CVE-2026-79116: Missing authorization in Viz. Reported by Google on 2026-04-13

[N/A][502344135] Medium CVE-2026-79006: Protection mechanism failure in HttpsUpgrades. Reported by Google on 2026-04-14

[N/A][502488051] Medium CVE-2026-79095: Information leak in Payments. Reported by Google on 2026-04-14

[N/A][502805441] Medium CVE-2026-79084: Inadequate encryption strength in Notifications. Reported by Google on 2026-04-15

[N/A][502888857] Medium CVE-2026-78991: Race condition in WebProtect. Reported by Google on 2026-04-15

[N/A][502918844] Medium CVE-2026-79248: Incorrect authorization in Input. Reported by Google on 2026-04-15

[TBD][503013378] Medium CVE-2026-78891: Buffer overflow in WebRTC. Reported by ngrunbaum on 2026-04-15

[N/A][503472696] Medium CVE-2026-79031: Improper resource exposure in Preload. Reported by Google on 2026-04-16

[N/A][503585863] Medium CVE-2026-79110: Missing authorization in Preload. Reported by Google on 2026-04-17

[N/A][503624894] Medium CVE-2026-79136: Incorrect authorization in ServiceWorker. Reported by Google on 2026-04-17

[N/A][503847023] Medium CVE-2026-78907: Incorrect authorization in WebProtect. Reported by Google on 2026-04-17

[N/A][504226770] Medium CVE-2026-79087: Injection in Chrome Tabs. Reported by Google on 2026-04-19

[N/A][504356442] Medium CVE-2026-79231: Buffer overflow in Media. Reported by Google on 2026-04-19

[N/A][504633668] Medium CVE-2026-78969: Uninitialized resource in Video. Reported by Google on 2026-04-20

[N/A][505951430] Medium CVE-2026-79137: Incorrect authorization in Extensions. Reported by Google on 2026-04-24

[N/A][505967344] Medium CVE-2026-79057: Race condition in Start. Reported by Google on 2026-04-24

[N/A][505991181] Medium CVE-2026-78894: Race condition in Payments. Reported by Google on 2026-04-24

[N/A][507483993] Medium CVE-2026-79264: Incorrect reference resolution in Preload. Reported by Google on 2026-04-28

[N/A][511260796] Medium CVE-2026-78910: Buffer overflow in V8. Reported by Google on 2026-05-08

[N/A][511736672] Medium CVE-2026-79066: Improper input validation in Navigation. Reported by Google on 2026-05-10

[N/A][511794959] Medium CVE-2026-79255: Improper input validation in WebRTC. Reported by Google on 2026-05-10

[N/A][511804361] Medium CVE-2026-79086: Missing authorization in CustomTabs. Reported by Google on 2026-05-10

[N/A][511806043] Medium CVE-2026-79038: Incorrect authorization in WebProtect. Reported by Google on 2026-05-10

[N/A][511819962] Medium CVE-2026-78940: Improper initialization in Network. Reported by Google on 2026-05-10

[N/A][511822878] Medium CVE-2026-79107: Incorrect authorization in TabGroups. Reported by Google on 2026-05-10

[N/A][512971896] Medium CVE-2026-79120: Uninitialized resource in ANGLE. Reported by Google on 2026-05-13

[N/A][513048462] Medium CVE-2026-79270: Uninitialized resource in ANGLE. Reported by Google on 2026-05-14

[N/A][513049445] Medium CVE-2026-79067: Missing authorization in Network. Reported by Google on 2026-05-14

[N/A][513119757] Medium CVE-2026-79213: Incorrect authorization in WebAppInstalls. Reported by Google on 2026-05-14

[N/A][513192145] Medium CVE-2026-78943: Improper input validation in Editing. Reported by Google on 2026-05-14

[N/A][513222422] Medium CVE-2026-79259: Improper input validation in Safebrowsing. Reported by Google on 2026-05-14

[N/A][513287677] Medium CVE-2026-79208: Missing authorization in HTTP2. Reported by Google on 2026-05-14

[N/A][513392351] Medium CVE-2026-79251: Improper input validation in Network. Reported by Google on 2026-05-15

[N/A][513607252] Medium CVE-2026-79226: Improper privilege management in Regional Capabilities. Reported by Google on 2026-05-15

[N/A][513608317] Medium CVE-2026-79042: Missing authorization in Payments. Reported by Google on 2026-05-15

[N/A][513608831] Medium CVE-2026-79122: Information leak in SignIn. Reported by Google on 2026-05-15

[N/A][513719741] Medium CVE-2026-79199: Incorrect authorization in Network. Reported by Google on 2026-05-16

[N/A][513737209] Medium CVE-2026-79013: Improper input validation in Sync. Reported by Google on 2026-05-16

[N/A][513745793] Medium CVE-2026-79074: Information leak in Network. Reported by Google on 2026-05-16

[N/A][513760788] Medium CVE-2026-79215: Integer overflow in WebGL. Reported by Google on 2026-05-16

[N/A][513786555] Medium CVE-2026-79049: Incorrect reference resolution in Passwords. Reported by Google on 2026-05-16

[N/A][513834155] Medium CVE-2026-79132: Improper input validation in Input. Reported by Google on 2026-05-16

[N/A][513836495] Medium CVE-2026-79201: Improper access control in Workers. Reported by Google on 2026-05-16

[N/A][513841856] Medium CVE-2026-79051: Incorrect authorization in Loader. Reported by Google on 2026-05-16

[N/A][513850062] Medium CVE-2026-79053: Missing authorization in Lighthouse. Reported by Google on 2026-05-16

[N/A][513918923] Medium CVE-2026-79285: Uninitialized resource in ANGLE. Reported by Google on 2026-05-17

[N/A][513923164] Medium CVE-2026-78906: Race condition in ANGLE. Reported by Google on 2026-05-17

[N/A][514006744] Medium CVE-2026-79250: UI misrepresentation in Navigation. Reported by Google on 2026-05-17

[N/A][514017820] Medium CVE-2026-79020: Out of bounds read in Skia. Reported by Google on 2026-05-17

[N/A][514055709] Medium CVE-2026-79217: Incorrect authorization in Mobile. Reported by Google on 2026-05-17

[N/A][514069975] Medium CVE-2026-79204: UI misrepresentation in Input. Reported by Google on 2026-05-17

[N/A][514078852] Medium CVE-2026-78912: UI misrepresentation in Browser. Reported by Google on 2026-05-17

[N/A][514439436] Medium CVE-2026-78955: Observable discrepancy in PerformanceAPIs. Reported by Google on 2026-05-18

[N/A][514454739] Medium CVE-2026-79143: Incorrect authorization in FileSystem. Reported by Google on 2026-05-19

[N/A][514508415] Medium CVE-2026-79241: Out of bounds read in GPU. Reported by Google on 2026-05-19

[N/A][514529599] Medium CVE-2026-78967: Missing authorization in BFCache. Reported by Google on 2026-05-19

[N/A][515477007] Medium CVE-2026-79214: Improper input validation in Preload. Reported by Google on 2026-05-21

[N/A][516398679] Medium CVE-2026-79228: Incorrect authorization in SiteIsolation. Reported by Google on 2026-05-25

[N/A][516665605] Medium CVE-2026-78953: Missing authorization in SiteIsolation. Reported by Google on 2026-05-26

[N/A][516824665] Medium CVE-2026-79229: Uninitialized resource in ANGLE. Reported by Google on 2026-05-26

[N/A][516899248] Medium CVE-2026-79002: Incorrect authorization in SiteIsolation. Reported by Google on 2026-05-26

[N/A][516921259] Medium CVE-2026-79272: Improper input validation in FindInPage. Reported by Google on 2026-05-27

[N/A][517045394] Medium CVE-2026-79127: Out of bounds write in ANGLE. Reported by Google on 2026-05-27

[N/A][517074167] Medium CVE-2026-79151: Improper input validation in Safebrowsing. Reported by Google on 2026-05-27

[N/A][517095594] Medium CVE-2026-78936: Observable discrepancy in CustomTabs. Reported by Google on 2026-05-27

[N/A][517245017] Medium CVE-2026-78905: Type confusion in ANGLE. Reported by Google on 2026-05-27

[N/A][517364411] Medium CVE-2026-79050: Incorrect authorization in Network. Reported by Google on 2026-05-28

[N/A][517382613] Medium CVE-2026-79008: Improper input validation in GPU. Reported by Google on 2026-05-28

[N/A][517398863] Medium CVE-2026-78975: Incorrect authorization in DOM. Reported by Google on 2026-05-28

[N/A][517404644] Medium CVE-2026-79287: Observable discrepancy in Forms. Reported by Google on 2026-05-28

[N/A][517467117] Medium CVE-2026-79094: Race condition in Workers. Reported by Google on 2026-05-28

[N/A][517487890] Medium CVE-2026-79173: UI misrepresentation in WebAppInstalls. Reported by Google on 2026-05-28

[N/A][517550421] Medium CVE-2026-78976: Improper input validation in StorageAccessAPI. Reported by Google on 2026-05-28

[N/A][517580738] Medium CVE-2026-79276: Improper privilege management in FileSystem. Reported by Google on 2026-05-28

[N/A][517606780] Medium CVE-2026-79191: Incorrect authorization in SiteIsolation. Reported by Google on 2026-05-28

[N/A][517608454] Medium CVE-2026-79099: Missing authorization in Network. Reported by Google on 2026-05-28

[N/A][517634590] Medium CVE-2026-79024: Information leak in ServiceWorker. Reported by Google on 2026-05-28

[N/A][517655953] Medium CVE-2026-79193: Information leak in Canvas. Reported by Google on 2026-05-28

[N/A][517697155] Medium CVE-2026-79242: Observable discrepancy in HTML. Reported by Google on 2026-05-29

[N/A][517719358] Medium CVE-2026-79180: UI misrepresentation in CustomTabs. Reported by Google on 2026-05-29

[N/A][517746687] Medium CVE-2026-79293: Information leak in Animation. Reported by Google on 2026-05-29

[N/A][517761566] Medium CVE-2026-79023: Incorrect authorization in Editing. Reported by Google on 2026-05-29

[N/A][517772510] Medium CVE-2026-79146: Information leak in CustomTabs. Reported by Google on 2026-05-29

[N/A][517774971] Medium CVE-2026-79238: Incorrect authorization in ServiceWorker. Reported by Google on 2026-05-29

[N/A][517910756] Medium CVE-2026-78949: Observable discrepancy in CustomTabs. Reported by Google on 2026-05-29

[N/A][518023156] Medium CVE-2026-79291: Information leak in CSS. Reported by Google on 2026-05-29

[N/A][518035396] Medium CVE-2026-79283: UI misrepresentation in Geometry. Reported by Google on 2026-05-29

[N/A][518053893] Medium CVE-2026-78892: Incorrect authorization in Chromoting. Reported by Google on 2026-05-30

[N/A][518062961] Medium CVE-2026-79070: Incorrect reference resolution in Cache. Reported by Google on 2026-05-30

[N/A][518065628] Medium CVE-2026-79205: Incorrect authorization in Network. Reported by Google on 2026-05-30

[N/A][518078552] Medium CVE-2026-78903: Incomplete cleanup in SiteIsolation. Reported by Google on 2026-05-30

[N/A][518084889] Medium CVE-2026-78959: Improper handling of case sensitivity in FileSystem. Reported by Google on 2026-05-30

[N/A][518094442] Medium CVE-2026-79234: Injection in CSS. Reported by Google on 2026-05-30

[N/A][519369088] Medium CVE-2026-78983: Use after free in Views. Reported by Google on 2026-06-03

[N/A][519984038] Medium CVE-2026-79083: Improper enforcement of behavioral workflow in Media. Reported by Google on 2026-06-04

[TBD][520052954] Medium CVE-2026-78944: Use after free in DevTools. Reported by yupyon.itome on 2026-06-05

[N/A][520117546] Medium CVE-2026-79178: Incorrect authorization in Web Authentication (Passkeys & Security Keys). Reported by Google on 2026-06-04

[N/A][520121111] Medium CVE-2026-79059: Information leak in BFCache. Reported by Google on 2026-06-04

[N/A][520179360] Medium CVE-2026-79245: Use after free in UI. Reported by Google on 2026-06-05

[N/A][520464738] Medium CVE-2026-78978: Out of bounds read in ANGLE. Reported by Google on 2026-06-05

[N/A][520481800] Medium CVE-2026-79103: Incorrect reference resolution in Speech. Reported by Google on 2026-06-05

[N/A][520492291] Medium CVE-2026-79154: Missing authorization in DevTools. Reported by Google on 2026-06-05

[N/A][520504922] Medium CVE-2026-79230: Improper input validation in ANGLE. Reported by Google on 2026-06-05

[N/A][520516462] Medium CVE-2026-79068: Improper resource exposure in StreamsAPI. Reported by Google on 2026-06-05

[N/A][520542088] Medium CVE-2026-79269: Uninitialized resource in ANGLE. Reported by Google on 2026-06-05

[N/A][522077127] Medium CVE-2026-79085: Missing authorization in Network. Reported by Google on 2026-06-10

[N/A][522351802] Medium CVE-2026-79134: Incorrect authorization in GetUserMedia. Reported by Google on 2026-06-10

[N/A][522550059] Medium CVE-2026-79064: Use after free in Network. Reported by Google on 2026-06-11

[N/A][522791354] Medium CVE-2026-79003: Incorrect authorization in Device. Reported by Google on 2026-06-11

[N/A][522823211] Medium CVE-2026-79220: Information leak in Network. Reported by Google on 2026-06-11

[N/A][522957054] Medium CVE-2026-78951: Use after free in ServiceWorker. Reported by Google on 2026-06-11

[N/A][523232966] Medium CVE-2026-79249: Code injection in Bisection. Reported by Google on 2026-06-12

[N/A][523557855] Medium CVE-2026-79091: Use after free in Bluetooth. Reported by Google on 2026-06-13

[N/A][523661149] Medium CVE-2026-79265: Incomplete cleanup in GetUserMedia. Reported by Google on 2026-06-13

[N/A][523716748] Medium CVE-2026-78913: Use after free in Chromoting. Reported by Google on 2026-06-14

[N/A][524418836] Medium CVE-2026-79258: Incorrect authorization in WebXR. Reported by Google on 2026-06-16

[TBD][524520965] Medium CVE-2026-79211: Incorrect authorization in USB. Reported by hongan on 2026-06-16

[N/A][524541667] Medium CVE-2026-79252: Information leak in ServiceWorker. Reported by Google on 2026-06-16

[N/A][524822825] Medium CVE-2026-78962: Uninitialized resource in WebXR. Reported by Google on 2026-06-17

[N/A][525686865] Medium CVE-2026-78901: Race condition in V8. Reported by Google on 2026-06-19

[N/A][525689847] Medium CVE-2026-79097: Use after free in V8. Reported by Google on 2026-06-19

[N/A][532162132] Medium CVE-2026-79227: Type confusion in DevTools. Reported by Google on 2026-07-07

[N/A][532182486] Medium CVE-2026-79203: Improper input validation in DevTools. Reported by Google on 2026-07-07

[N/A][532914769] Medium CVE-2026-79033: Insufficient control flow management in DevTools. Reported by Google on 2026-07-09

[N/A][532917452] Medium CVE-2026-79139: Improper input validation in Media. Reported by Google on 2026-07-09

[N/A][532923954] Medium CVE-2026-79221: Uninitialized resource in Dawn. Reported by Google on 2026-07-09

[N/A][532957785] Medium CVE-2026-79034: Information leak in CORS. Reported by Google on 2026-07-09

[N/A][533093250] Medium CVE-2026-79075: Information leak in Geolocation. Reported by Google on 2026-07-09

[TBD][533917984] Medium CVE-2026-78960: Information leak in Extensions. Reported by Oran Simhony from Palo Alto Networks on 2026-07-12

[N/A][535374213] Medium CVE-2026-78984: Uninitialized resource in GPU. Reported by Google on 2026-07-16

[N/A][536428842] Medium CVE-2026-78963: Improper input validation in Media. Reported by Google on 2026-07-19

[N/A][536428988] Medium CVE-2026-79004: Out of bounds read in Media. Reported by Google on 2026-07-19

[N/A][536444242] Medium CVE-2026-79182: Improper input validation in Media. Reported by Google on 2026-07-19

[TBD][536526176] Medium CVE-2026-79185: Information leak in DOM. Reported by avlidienbrunn on 2026-07-19

[N/A][536662911] Medium CVE-2026-79073: Improper state validation in Parser. Reported by Google on 2026-07-20

[N/A][537145191] Medium CVE-2026-79266: Use after free in DevTools. Reported by Google on 2026-07-21

[N/A][537846307] Medium CVE-2026-79025: Improper input validation in Workers. Reported by Google on 2026-07-22

[TBD][538969297] Medium CVE-2026-79141: Incorrect authorization in Browser. Reported by M. Fauzan Wijaya (Gh05t666nero) on 2026-07-25

[$1,000][503048520] Low CVE-2026-78974: UI misrepresentation in Linux Toolkit Theming. Reported by Francesco Topol on 2026-04-16

[N/A][497232609] Low CVE-2026-79055: Information leak in Sharing. Reported by Google on 2026-03-28

[N/A][497256260] Low CVE-2026-79263: Race condition in Extensions. Reported by Google on 2026-03-28

[N/A][497493136] Low CVE-2026-79124: Information leak in Intents. Reported by Google on 2026-03-29

[N/A][497499482] Low CVE-2026-79184: Missing authorization in Preload. Reported by Google on 2026-03-29

[N/A][497876969] Low CVE-2026-79289: Improper control of a resource through its lifetime in Workers. Reported by Google on 2026-03-30

[N/A][500484520] Low CVE-2026-79001: Information leak in Bluetooth. Reported by Google on 2026-04-07

[N/A][501416859] Low CVE-2026-79077: Incorrect authorization in WebProtect. Reported by Google on 2026-04-10

[TBD][501881082] Low CVE-2026-78950: Integer overflow in WebRTC. Reported by Ashutosh on 2026-04-12

[N/A][502252964] Low CVE-2026-79196: Race condition in Editing. Reported by Google on 2026-04-13

[N/A][502514083] Low CVE-2026-79000: Improper input validation in DeviceBoundSessionCredentials. Reported by Google on 2026-04-14

[N/A][503720291] Low CVE-2026-78979: Race condition in Core. Reported by Google on 2026-04-17

[N/A][506539337] Low CVE-2026-79181: Observable discrepancy in Glic. Reported by Google on 2026-04-26

[N/A][513172858] Low CVE-2026-79190: Incorrect authorization in Extensions. Reported by Google on 2026-05-14

[N/A][513361380] Low CVE-2026-79206: Out of bounds read in FileSystem. Reported by Google on 2026-05-15

[N/A][513486883] Low CVE-2026-78897: Missing authorization in BrowserTag. Reported by Google on 2026-05-15

[N/A][513688690] Low CVE-2026-79119: Use after free in PDF. Reported by Google on 2026-05-15

[N/A][513792983] Low CVE-2026-79089: Race condition in Transactions Platform. Reported by Google on 2026-05-16

[N/A][513969378] Low CVE-2026-79147: Information leak in Skia. Reported by Google on 2026-05-17

[N/A][514010111] Low CVE-2026-79098: UI misrepresentation in PermissionElement. Reported by Google on 2026-05-17

[N/A][514038302] Low CVE-2026-79022: UI misrepresentation in Transactions Platform. Reported by Google on 2026-05-17

[N/A][514061923] Low CVE-2026-79233: UI misrepresentation in CustomTabs. Reported by Google on 2026-05-17

[N/A][514408247] Low CVE-2026-79261: Incorrect authorization in Controls. Reported by Google on 2026-05-18

[N/A][516864349] Low CVE-2026-78977: Uninitialized resource in GPU. Reported by Google on 2026-05-26

[N/A][516950646] Low CVE-2026-79040: Uninitialized resource in GPU. Reported by Google on 2026-05-27

[N/A][517167020] Low CVE-2026-79273: Incorrect reference resolution in WebView. Reported by Google on 2026-05-27

[TBD][517394060] Low CVE-2026-79243: Improper input validation in ReadingList. Reported by Orange Tsai (@orange_8361) of DEVCORE Research Team on 2026-05-28

[TBD][517395590] Low CVE-2026-79123: Improper input validation in NTP Footer. Reported by Orange Tsai (@orange_8361) of DEVCORE Research Team on 2026-05-28

[N/A][517540292] Low CVE-2026-79005: Incorrect authorization in StorageAccessAPI. Reported by Google on 2026-05-28

[N/A][517673944] Low CVE-2026-79090: Improper privilege management in Actor. Reported by Google on 2026-05-29

[N/A][517718241] Low CVE-2026-78946: Incorrect authorization in Select. Reported by Google on 2026-05-29

[N/A][518125889] Low CVE-2026-78968: Missing authorization in Core. Reported by Google on 2026-05-30

[N/A][518249083] Low CVE-2026-79041: Missing authorization in Browser. Reported by Google on 2026-05-30

[N/A][519210950] Low CVE-2026-79284: UI misrepresentation in Core. Reported by Google on 2026-06-02

[N/A][519229463] Low CVE-2026-78896: Information leak in StorageAccessAPI. Reported by Google on 2026-06-02

[N/A][519242511] Low CVE-2026-79058: Missing authorization in Passwords. Reported by Google on 2026-06-02

[N/A][519246298] Low CVE-2026-79009: UI misrepresentation in UI. Reported by Google on 2026-06-02

[N/A][519254827] Low CVE-2026-79060: Incorrect authorization in StorageAccessAPI. Reported by Google on 2026-06-02

[N/A][520002854] Low CVE-2026-79177: Incorrect authorization in Media. Reported by Google on 2026-06-04

[N/A][520016142] Low CVE-2026-78956: Type confusion in V8. Reported by Google on 2026-06-04

[TBD][520781436] Low CVE-2026-79239: Out of bounds read in Tint. Reported by Michal Andryskowski, Imperial College London on 2026-06-07

[N/A][522291712] Low CVE-2026-79015: Improper input validation in ServiceWorker. Reported by Google on 2026-06-10

[N/A][522304549] Low CVE-2026-79108: UI misrepresentation in Web Authentication (Passkeys & Security Keys). Reported by Google on 2026-06-10

[N/A][522418913] Low CVE-2026-79056: Use after free in ServiceWorker. Reported by Google on 2026-06-10

[N/A][522803735] Low CVE-2026-79018: Information leak in FoldableAPIs. Reported by Google on 2026-06-11

[N/A][523237735] Low CVE-2026-78980: Improper input validation in ReaderMode. Reported by Google on 2026-06-12

[N/A][523313378] Low CVE-2026-78947: Incomplete cleanup in Chromium. Reported by Microsoft Edge on 2026-06-12

[N/A][523572877] Low CVE-2026-79244: Use after free in Animation. Reported by Google on 2026-06-13

[TBD][524864599] Low CVE-2026-79112: Out of bounds read in Skia. Reported by Quan Huynh x Amaterasu on 2026-06-17

[N/A][525311654] Low CVE-2026-79246: Information leak in DataTransfer. Reported by Google on 2026-06-18

[TBD][530816571] Low CVE-2026-79223: Integer overflow in Chromium. Reported by Youngjin Ju on 2026-07-03

[N/A][531245718] Low CVE-2026-79045: Type confusion in V8. Reported by Google on 2026-07-04

[N/A][531297707] Low CVE-2026-79197: Use after free in V8. Reported by Google on 2026-07-05

[N/A][532303080] Low CVE-2026-79148: Off-by-one error in DevTools. Reported by Google on 2026-07-08

[N/A][533001362] Low CVE-2026-79125: Information leak in XR. Reported by Google on 2026-07-09

[N/A][533014006] Low CVE-2026-79207: Information leak in Passwords. Reported by Google on 2026-07-09

[N/A][533021205] Low CVE-2026-79017: Race condition in Extensions. Reported by Google on 2026-07-09

[N/A][533046298] Low CVE-2026-79105: Improper input validation in Mobile. Reported by Google on 2026-07-09

[N/A][533059149] Low CVE-2026-79225: Incorrect authorization in Browser. Reported by Google on 2026-07-09

[N/A][533060125] Low CVE-2026-79021: Missing authorization in InterestGroups. Reported by Google on 2026-07-09

[N/A][533075126] Low CVE-2026-79133: Incorrect authorization in Forms. Reported by Google on 2026-07-09

[N/A][533079345] Low CVE-2026-79179: Incorrect authorization in DOM. Reported by Google on 2026-07-09

[N/A][533083384] Low CVE-2026-79152: Incorrect authorization in CustomTabs. Reported by Google on 2026-07-09

[N/A][533121405] Low CVE-2026-78981: Information leak in Mobile. Reported by Google on 2026-07-09

[N/A][533123348] Low CVE-2026-78957: Information leak in Mobile. Reported by Google on 2026-07-09

[N/A][533408915] Low CVE-2026-79126: Incorrect provision of specified functionality in Proxy. Reported by Google on 2026-07-10

[N/A][533418127] Low CVE-2026-78915: Race condition in Enterprise. Reported by Google on 2026-07-10

[N/A][533511921] Low CVE-2026-79253: Improper input validation in Network. Reported by Google on 2026-07-10

[N/A][533511967] Low CVE-2026-79260: Improper input validation in Cookies. Reported by Google on 2026-07-10

[N/A][534556413] Low CVE-2026-79254: Incorrect reference resolution in CustomTabs. Reported by Google on 2026-07-14

[N/A][536166543] Low CVE-2026-78914: Uninitialized resource in Skia. Reported by Google on 2026-07-18

[N/A][539341100] Low CVE-2026-78964: Use after free in Sync. Reported by Google on 2026-07-27


We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.


Many of our security bugs are detected using AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, or AFL.


Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.


Srinivas Sista

Google Chrome

  •  

v1.9.0 - Fullscreen Email & Pro Split-Screen, Mobile Swipe Actions, and Configurable List Ordering

1.9.0 (2026-08-25)

Thank you for your donations:

One-time

Monthly

Features

  • Mail: Fullscreen email view in the standard interface
  • Mail: Drag a mail onto a new browser tab to open it fullscreen
  • Mail: Configurable message-list ordering (#718)
  • Mail: Search suggestions with recent searches and contact autocomplete (#845)
  • Mail: Render plain-text emails in the app font by default, with a monospace option (#830)
  • Mail: Pull-to-refresh indicator while dragging the list down (#826)
  • Mail: Redesigned unread favicon badge — a compact keyline badge
  • Mobile: Swipe message rows left or right for quick actions — archive, delete, toggle read, toggle star, or spam, configurable per direction, RTL-aware
  • Pro: Reworked split-screen shell with per-pane tab strips, drag & drop between panes, and pane-scoped overlays
  • Pro: Folder tabs via drag & drop
  • Pro: The address bar follows the focused tab, and deep links are delivered live to already-mounted surfaces
  • Composer: Real byte progress for attachment uploads, stock and plugin-offloaded; cancel now aborts the transfer itself
  • Calendar: Moving an event's start moves the end with it, keeping the event's length
  • Contacts: Trusted Senders address book enabled by default on contacts-capable accounts
  • Settings: Custom time zone setting that overrides browser detection (#755)
  • Login: Server dropdown on the OAuth-only login screen (#799)
  • Push: New-mail notifications grouped per account with a "+N more messages" line instead of one notification per message
  • Push: Per-device revoke for push subscriptions (#841)
  • Admin: Configurable Stalwart admin access to the dashboard (#870)
  • Admin: Push relay picked from an admin-defined list instead of a free URL field
  • Branding: OpenGraph/Twitter link previews with a generated card image
  • Performance: Halved time-to-mail-list — lazy locale catalogs, code-split viewer and composer, shorter auth waterfall, boot snapshot
  • i18n: Mongolian translation
  • Plugins: jmap.uploadBlob
  • Plugins: onBeforeComposeOpenToReply and sibling hooks let a plugin edit an email before it populates the composer for reply or forward
  • Plugins: getPublicKeyFromWKD
  • Plugins: Privileged plugins can fetch a byte range of a blob
  • Plugins: progressFileId on api.http.post so an offloaded upload reports byte progress to the composer chip
  • Plugins: isActive on AccountResponse
  • Plugins: Label settings and label reordering exposed to extensions
  • Plugins: JMAP keyword helpers and gateway keywords exposed to extensions
  • Plugins: Mailbox refresh hook
  • Dev: AddressBook/set in the dev mock JMAP server

Changes

  • Plugins: The PRF getOrCreate flow is split into separate get and create steps for better authenticator compatibility (#851)
  • Dependencies: Next 16.3.3, pdfjs-dist 6.2.108, DOMPurify 3.4.14 (npm audit)

Fixes

  • Send: Route scheduled sends to the account that owns the submission — mail scheduled from a shared address can now be listed, cancelled, and rescheduled instead of going out silently (#874)
  • Send: Split recipient lists whose angle brackets never close without dropping recipients
  • Send: generateMessageId crashed on insecure origins (crypto.randomUUID undefined), failing the send after the draft save
  • Composer: Keep attachments when re-opening a draft, also in the Pro draft tab, and destroy old draft versions only after a successful create or send (#849)
  • Composer: Keep the signature in saved drafts and embed it into re-opened drafts (#848)
  • Composer: Double-click unlocks the embedded signature for editing
  • Composer: Keep already written text when applying a template (#540)
  • Composer: Preselect the shared folder's identity for new messages
  • Composer: Namespace all accounts consistently in the Pro composer identity list
  • Composer: Opening a mailto: link runs the unsaved-draft dialog instead of replacing the draft outright
  • Composer: Keep the fresh-compose tab title clear of the selected email subject
  • Composer: Clear the viewer when sending destroys the displayed draft
  • Reply: Honour an external Reply-To even on a self-sent message
  • Mail: Flip $junk/$notjunk keywords on spam and not-spam (#850)
  • Mail: Remove keywords with null rather than false in Email/set, per RFC 8620
  • Mail: Escape the JSON Pointer in keyword patches so nested tags like work/clients patch the right keyword
  • Mail: Route keyword writes — tags, pins, flags — to the selected shared account so they persist
  • Mail: Route shared-folder management to the owner account, scoped to one server
  • Mail: Open the right conversations in a shared mailbox (#814)
  • Mail: Route multi-account email lookups and invitation parsing by source account (#847), and parse invitations in directly viewed shared folders against the folder owner (#867)
  • Mail: Folders containing a system folder name no longer disappear from the sidebar (#771)
  • Mail: Folder drag & drop can move folders into other parents (#855)
  • Mail: Keep the folder tree when a refresh burst hits maxConcurrentRequests (#780)
  • Mail: Stop All-Mail and cross-account views emptying on delete, star, or mark-read (#791)
  • Mail: Keep just-read or unstarred mail in the open Unread/Starred view
  • Mail: Search folder filter defaults to all folders and persists (#788)
  • Mail: Fixed-width read/unread toolbar button so buttons don't jump when a message opens (#864)
  • Mail: Transparent hover-action background on tagged rows
  • Mail: Enforce the external media preference on plugin-rendered bodies (#797)
  • Mail: Apply the data: URI allowlist to media tags and srcset candidates too
  • Mail: Make label reordering atomic
  • Mail: Pass PDF bytes to pdf.js instead of fetching the blob: URL that CSP connect-src blocks (#871)
  • Mail: Include email templates in cross-device settings sync (#825)
  • Mail: Toast store crashed on insecure origins, breaking every post-action acknowledgement
  • Mobile: Reach the tag and move submenus in the more-actions menu (#779)
  • Mobile: iOS Safari no longer zooms the viewport on every input focus (#838)
  • Calendar: Click and double-click create events at the clicked slot instead of near the current time
  • Calendar: Save and Cancel are available when an event is created, and the toolbar no longer overflows in edit mode
  • Calendar: Edit a single recurring occurrence via a one-shot override patch
  • Calendar: Hide tasks-only calendars from the event calendar
  • Calendar: Exclude subscription and read-only calendars from event creation (#762)
  • Calendar: Rights-first event editability, including alias organizers
  • Calendar: Pin supported-calendar-component-set on created calendars (#760)
  • Calendar: Gate first-touch calendar and contacts requests to stop duplicate default calendars (#907)
  • Calendar/Contacts: Namespace all accounts consistently on switch, so multi-account address-book aggregation and calendar selection survive an account switch
  • Contacts: Import vCard dates as RFC 9553 PartialDate and map common X- extensions (#224)
  • Files: Decode percent-encoded FileNode names from WebDAV-created nodes (#869)
  • Files: Reset the account-scoped Files drive on every account switch
  • Accounts: Refresh the account display name from the Stalwart principal on login, restore, and switch (#900)
  • Auth: Reuse the cached access token on session restore (#552)
  • Auth: Refresh TOTP-minted tokens with the default client id when no OAuth client is configured (#873)
  • Auth: Store the session cookie for relative JMAP server URLs
  • Security: Close IPv6 transition-address and redirect bypasses in the endpoint guard
  • Security: Add embedded custom app origins to CSP frame-src (#787)
  • Security: Per-account isolation for encryption at rest
  • JMAP: Cap live SSE streams per tab and keep exactly one stream per client, so many logins can't starve JMAP requests (#702)
  • JMAP: Check the specific capability a request declares (principals:owner), not a broader one
  • JMAP: Resolve relative session URLs without corrupting URI templates
  • Settings: Merge per-account maps on server load, fixing the compose identity switch
  • Settings: Leaving the Pro interface returns to the surface in use and keeps the settings scroll position
  • UI: Position portalled popovers before first paint to stop the layout flash on open
  • Push: Recreate the push subscription on re-register (#841)
  • i18n: Key parity across all 24 locales, Catalan and Mongolian registered in the client provider, and scoped translation hooks instead of relative namespace paths
  • Docs: Lengthen the example SESSION_SECRET so it meets the minimum length

  •  

Icons! Lots of them! – These Weeks in Firefox: Issue 206

Highlights

  • Starting in Firefox 154, we’ve added a new capability for changing the default browser icon for Windows (Windows-only, for now, and not MSIX / Store installs) in about:settings#appearance!

Menu under Appearance settings containing a list of icons to choose from to customize the Firefox browser icon.

Settings panel checkbox to enable stylesheet handling in the debugger.

  • The Picture-in-Picture WebAPI is now available, starting with release version Firefox 153!
    • This does not replace the built-in Picture-in-Picture mechanism, and is in fact powered by it.

Friends of the Firefox team

Resolved bugs (excluding employees)

Volunteers that fixed more than one bug

  • japandi

New contributors (🌟 = first patch)

Project Updates

Add-ons / Web Extensions

Addon Manager & about:addons
  • As part of Project Nova work:
    • Added moz-promo cards to the about:addons extensions list recommendations footer and empty state, and updated the openAmoInTab helper to support a custom UTM content value – Bug 2043615 / Bug 2050880
    • Introduced the building blocks for the Nova Themes Picker in about:addons: a shared Firefox Themes list source of truth, a light/dark/device theme-mode switcher, a reusable theme-preview webcomponent, and Nova-styled theme previews – Bug 2051554 / Bug 2051559 / Bug 2051564 / Bug 2051573
    • Updated the Extensions panel empty state illustration and toolbar item icon for Project Nova – Bug 2030715
      • Thanks to Michael Hynson for driving this.
  • Removed the legacy AddonManager Glean metrics used for mirroring legacy telemetry events, along with the corresponding legacy telemetry test checks – Bug 1923949 / Bug 1981822
    • Thanks to Chris H-C for collaborating with us on this.
  • Fixed themes installed through the distribution mechanism not fetching their AMO metadata, which was resulting in distribution installed themes left without a preview image in about:addons – Bug 1917279
    • Thanks to Mike Kaply for the fix to the distribution themes metadata handling.
  • Fixed amContentHandler to verify that a system triggeringPrincipal genuinely originated from the parent process, a regression introduced in Firefox 153 and fixed in Firefox 154 (with a beta 153 uplift requested) – Bug 2048964
WebExtensions Framework
  • Fixed a startup performance regression by avoiding an NSS-initializing crypto.getRandomValues() call during extension startup, a regression introduced in Firefox 153 and fixed in Firefox 154 (with a beta 153 uplift requested) – Bug 2050882
  • Enabled tier 3 TypeScript typecheck linting for the extensions framework code – Bug 2050124
  • Implemented the WebExtensions manifest sandbox key, letting extensions keep using string-based code execution in unprivileged sandboxed extension documents – Bug 1685123
    • Thanks to Robin for the implementation of the manifest sandbox support.
WebExtension APIs
  • Enabled storage.local database auto-reset on detected corrupted IndexedDB storage on all channels, starting in Firefox 154 – Bug 1992973
  • Simplified registerTraceableChannel to make it synchronous again, removing the delay before blocking webRequest listeners can register a traceable channel – Bug 2044518
  • Restored the contextualIdentities iconUrl container icons to their intrinsic 32×32 size, fixing a regression introduced earlier in the Firefox 154 cycle – Bug 2048599
    • Thanks to Andrea Marchesini for the fix to the contextualIdentities container icons.
  • Fixed the MV2 userScripts API failing with an Xrays TypedArray access error due to a missing isWebExtensionContentScript flag – Bug 2054083
    • Thanks to erosman for the fix to the MV2 userScripts API.

DevTools

The visually updated about:debugging Performance dialog

  • Nicolas Chevobbe about:debugging is now using moz-page-nav for its left sidebar (#2048544), thanks to Mark making it possible to disable collapsing that occurs on narrow screen (#2050907)
    • (not all items were migrated to moz-page-nav-button though, see #2050746 for remaining work)
  • Alexandre Poirot made it possible to control the request and response body size limit from the Settings panel (#2040892)

A control in the Firefox DevTools Settings panel to adjust the request and response body size limit.

A notification displayed above the DevTools Inspector panel promoting Local Mode.

WebDriver

Credential Management

Migration Improvements

New Tab Page

  • That’s a wrap for the World Cup! We’re powering down the Sports widget today.
    • Some folks might see a survey about the Sports widget, to get feedback from the wild on whether or not it provided any user value (Telemetry points to “yes”, but it’s good to get qual data too)
    • We’re replacing it with some new widgets. If you’re in an English-speaking region, you will probably see it replaced with a Daily Crossword widget. Otherwise, it’ll be replaced with a Picture of the Day widget.
  • Sections have rolled out to 100% in France! We’re now doing 10% Sections experiments in Spain, Italy, Austria, Switzerland and Belgium.
  • Shout out to volunteer Sameeksha who added an accessible name to the Task list widget ••• button, adding an aria-label/accessible-name so NVDA/VoiceOver announce the control and keyboard navigation/activation works correctly on New Tab.
  • Joel added WebNotifications to the newtab state, allowing New Tab widgets to observe and reflect WebNotification events (affects the notification-driven widget lifecycle and UI state updates).
  • Reem Hamoui adjusted the New-Tab Widgets 3-dot menu layout to vertically center menu entries inside the hover-granted colorful stripe, removing visual misalignment and small hit-area offsets on touch and pointer inputs.
  • Dre implemented the show less/show more transition animation for New Tab expand/collapse, smoothing layout shifts with a CSS transition to reduce perceived jank during widget list changes.
  • Scott Downe fixed New Tab Page drag-and-drop so widgets no longer jump or keep moving during drags (2049472).
  • Reem Hamoui rendered the Daily Crossword in a sandboxed iframe to isolate its scripts/CSP on the New Tab Page (2049489).
  • Reem Hamoui added the Crossword option to about:preferences and wired the New Tab Page crossword widget into prefs (2050340), so users can enable or disable the crossword via the standard Preferences UI rather than about:config.
  • Dre set up the Picture of the Day boilerplate, including prefs and basic New Tab UI components (2050969), which exposes a configurable PoD surface for users to opt into and customize.
  • Dre added a dismiss control and persisted dismissal state to the daily photo UI (2050972), allowing users to remove the current picture from their New Tab and avoid immediate reappearance.
  • Dre added a “set as wallpaper” action and hooked it into New Tab wallpaper storage/prefs (2050973), enabling users to promote a PoD image to their custom New Tab wallpaper persistently.
  • Dre connected the Picture of the day widget to the Merino endpoint to set the background of the widget to the current picture (2050976). He also added telemetry for the Picture of the day widget on the New Tab Page to capture impressions and clicks for usage analysis (2050977).
  • Nina Pypchenko [:nina-py] added a small size variant for the Focus Timer widget in Nova so the timer can render compactly in narrow/new tab layouts and reduce vertical space usage (2051179).
  • Maxx Crawford created a DevTools ‘controls’ area on the New Tab Page to enable and configure the widget, exposing toggles and settings that let developers and experimenters flip the widget without changing prefs, which reduces friction when reproducing NTP widget behaviors during debugging and testing.
  • Irene Ni switched the New Tab ‘inferred personalization’ checkbox to the platform moz-checkbox control, restoring native checkbox semantics (role/keyboard focus/visual state) so users toggling inferred personalization see consistent a11y behavior and platform rendering across Windows/macOS/Linux.
  • Scott Downe fixed an intermittent visual reload/flicker of sponsored tiles and the Add Shortcut button when pinning/unpinning shortcuts, preventing momentary tile DOM reflows and layout thrash that caused perceived data loss or longer perceived latency during shortcut edits.
  • Scott Downe ensured custom image URLs persist on manually added Top Site tiles after edit, so users’ uploaded or external thumbnails no longer revert to the site’s homepage preview when saving edits and their custom thumbnails are correctly cached and displayed.
  • Dre introduced two variants of the World Cup widget survey message, changing the copy delivered in the widget to support an A/B/message-variant experiment and altering what users see when the World Cup widget surfaces survey prompts on their New Tab Page.
  • Nina Pypchenko [:nina-py] introduced a default state for Medium and Large Stocks widget sizes on the New Tab Page to surface placeholder content and avoid blank tiles when the Stocks feed is empty or slow to load.
  • Nina Pypchenko [:nina-py] added an error state to the Stocks widget on the New Tab Page to show an explicit failure UI when quote fetches or network requests fail, reducing user confusion.
  • Alexandre Hanot migrated AdsFeed to fetch New Tab ads through the MozAdsClient, changing the ad retrieval path (AdsFeed -> MozAdsClient) which affects ads loading behavior and telemetry for users who see New Tab Page ads.
  • Irene Ni fixed the New Tab add-pin flow that was creating extra rows when grouped pins was off by changing the insertion logic to append into the existing grid, which eliminates unexpected row creation and layout shifts for users managing many pins (2053251).
  • Scott Downe updated New Tab section rendering to hide cards that don’t fill their row by adjusting layout logic/CSS, removing orphaned placeholders and reducing blank space on narrow viewports or low-item sections for a cleaner grid appearance (2053264).
  • Reem Hamoui added a context menu to the Crossword widget using a postMessage integration between the iframe and parent page, enabling right-click actions (copy/hint/theme) and making the embedded crossword more interactive and accessible to users who rely on context menus (2053311).
  • Reem Hamoui added a visible “New” badge plus interaction handlers and state tracking to the Crossword widget on the New Tab Page to improve discoverability and make tapping/clicking behave reliably when launching puzzles (2053667).
  • Irene Ni removed unused Add Shortcut OMC artifacts from the New Tab Page (2053843); this is a cleanup of obsolete assets/templates and has no direct runtime user impact.
  • Maxx Crawford added author and license attribution to the Picture of the Day widget (2053933); this surfaces photographer credit and license metadata on the New Tab Page for users who want provenance information.
  • Maxx Crawford applied UX refinements to the Picture of the Day widget (2054109); users will see improved layout, spacing, and touch targets in the POTD area for clearer interactions.
  • Maxx Crawford added a pref and trainhopConfig gate to toggle the POTD “Set as wallpaper” feature (2054111); rollout and availability of the wallpaper action are now controllable via pref and remote trainhopConfig.
  • Maxx Crawford added a dedicated trainhopConfig.widgetPictureOfTheDay payload for POTD feature config (bug 2054112) so the New Tab Page train-hop widget can be controlled server-side — this delivers image URLs, attribution and display params remotely which lets us enable/disable POTD per cohort without ship-side changes and reduces rollout latency for users who see the Picture‑of‑the‑Day widget.
  • Irene Ni updated the Shortcuts Add/Edit dialog for Nova (bug 2054175) to improve the add/edit UX on the New Tab Shortcuts surface — the patch adjusts dialog layout and controls, tightens validation and accessibility labels, and reduces accidental duplicate/invalid shortcut creation so users editing shortcuts have a more reliable, faster flow.
  • Maxx Crawford fixed the Daily crossword widget content overflowing and clipping past the bottom container boundary by adjusting the crossword widget’s layout/CSS (container height calculations and overflow/overflow-anchor rules) on the New Tab Page, restoring full visibility of clues and controls across responsive breakpoints.
  • Maxx Crawford fixed Related articles not opening on click by repairing the related-articles component’s click handling and event delegation (anchor href/target behavior and JS listener) on the New Tab Page so article tiles now reliably open on click for users.
  • Maxx Crawford added a “New” badge and interactions to the Picture of the Day widget, implementing an isNew flag, local state/localStorage handling, ARIA label updates and click behavior so users can immediately see and act on newly added images.
  • Maxx Crawford updated the initial order of the Picture of the day widget by changing the PoD component’s initial ordering/priority algorithm so first-run and default NTP surfaces surface curated/high-priority images first.
  • Maxx Crawford migrated Crossword widget strings from Fluent back to inline markup to fix localization/formatting regressions in the crossword UI and ensure consistent rendering of labels and controls across locales.
  • Irene Ni migrated the New Tab Widgets expand button to moz-button which standardizes the expand/collapse control on the New Tab Page widgets area, fixing inconsistent styling and keyboard/click handling so users now get consistent visuals and improved accessibility across platforms.
  • Reem Hamoui added a dedicated trainhopConfig.widgetCrossword payload for Crossword feature config which isolates crossword rollout flags and content settings from other trainhop payloads, allowing targeted remote-config changes and safer A/B testing of the crossword widget without impacting unrelated New Tab features.
  • Maxx Crawford fixed the Daily crossword widget being blank after closing and reopening the browser by ensuring widget state is correctly initialized/persisted on startup (New Tab Page widget lifecycle), so users now reliably see the daily puzzle after a restart instead of an empty frame.
  • Reem Hamoui fixed Daily crossword completed puzzle and show clues are displayed in medium sized widget, restoring completed-puzzle rendering and clue visibility in the New Tab Page medium widget (widget template/CSS).
  • Maxx Crawford updated Discovery Stream Admin buttons to use moz-button components, replacing custom controls with moz-button to standardize admin UI styling and focus behavior.
  • Maxx Crawford added per-widget feature toggles and pref reset buttons to Discovery Stream Admin, enabling admins to toggle individual widgets and reset prefs without code deploys — changes here can alter what users see when toggled.
  • Maxx Crawford migrated Discovery Stream Admin unit tests to jest, moving tests to Jest for faster developer feedback and more consistent test tooling.
  • Maxx Crawford enforced Fail jest tests that emit console.error messages, making tests fail on console.error to catch regressions earlier and improve content quality before release.
  • Kyle Jones populated MozAdsRequestOptions flags from adsBackendConfig in AdsFeed on the New Tab Page, changing ad request parameters that may alter which ads or personalization users see.
  • Mike Conley removed the version 145 train-hop shim for the PrivacyFeed getTodayStats guard, simplifying guard logic in the New Tab Page with no direct user-visible change.

Search and Urlbar

Search
  • Mandy fixed the “New” label incorrectly appearing for user-installed third party search engines that override application-provided engines (2053710).
  • Standard8 fixed search engine telemetry notifications and private browsing search engine defaults (2053129, 1792669).
Suggest
  • Adw added header_text support for AMP (AdMarketPlace) suggestions (2053626).
Nova
Address Bar
Places & Bookmarks

Storybook/Reusable Components/Acorn Design System

  • Nova stuff
  • Theme Picker for HNT, OMC and Profiles
  • [mconley] There’s a new vertical variant for visual picker. Thanks for the reviews, hjones!
  •  

v12.3.1

✨ New Features & Improvements

  • @directus/api
    • Added countFilterListeners, countActionListeners, and countInitListeners methods to the emitter, exposing the number of registered handlers for each event (#28117 by @ComfortablyCoding)

🐛 Bug Fixes & Optimizations

  • @directus/app
    • Fixed MCP OAuth clients settings pages concatenating breadcrumbs into the page title (#28115 by @MHJahanbakhsh)
  • @directus/api
    • Fixed the WebSocket heartbeat leaking a websocket.message listener on each ping when a client failed to respond in time (#28117 by @ComfortablyCoding)
    • Fixed GraphQL query fragments returning null fields (#28128 by @ComfortablyCoding)
    • Fixed public registration verification using the provided email instead of the stored one (#28144 by @br41nslug)
    • Removed user_created and date_created for update from recommended permissions for directus_shares (#28145 by @br41nslug)
    • Updated storage driver dependencies (#28119 by @ComfortablyCoding)
  • @directus/cli
    • Stripped project_id when pulling settings, so a sync no longer copies one instance's identity onto another (#28132 by @lazerg)
  • @directus/sdk
    • Fixed unsubscribe() not removing subscriptions, causing them to persist across reconnects and accumulate for the lifetime of the client (#28117 by @ComfortablyCoding)
  • @directus/system-data
    • Removed user_created and date_created for update from recommended permissions for directus_shares (#28145 by @br41nslug)
  • @directus/storage-driver-s3
  • @directus/storage-driver-gcs
  • @directus/storage-driver-azure
  • @directus/storage-driver-supabase

📦 Published Versions

  • @directus/app@17.1.1
  • @directus/api@39.1.0
  • @directus/cli@12.2.1
  • @directus/composables@11.6.2
  • create-directus-extension@12.1.4
  • @directus/env@6.2.2
  • @directus/extensions@4.0.4
  • @directus/extensions-sdk@18.0.4
  • @directus/memory@4.0.4
  • @directus/pressure@4.0.4
  • @directus/storage-driver-azure@13.0.4
  • @directus/storage-driver-cloudinary@14.0.1
  • @directus/storage-driver-gcs@13.0.4
  • @directus/storage-driver-s3@14.0.1
  • @directus/storage-driver-supabase@5.0.1
  • @directus/system-data@4.6.1
  • @directus/themes@2.0.4
  • @directus/utils@13.5.4
  • @directus/validation@3.0.4
  • @directus/sdk@25.0.1

  •  

Minecraft 26.3-snapshot-10 (snapshot) Released

26.3 Snapshot 10 (known as 26.3-snapshot-10 in the launcher) is the tenth snapshot for Java Edition 26.3, released on August 25, 2026, which changes the panorama for the next game drop, renames explorer maps, and fixes bugs. Full changelog: https://minecraft.wiki/Java_Edition_26.3-snapshot-10
  •  
❌