Lees weergave

v4.3.11

Features

  • Added asynchronous DNS validation for application and service domains.
  • Added one-click service templates for HashiCorp Vault and Obsidian LiveSync CouchDB.

Fixes

  • Restored proxy connections to project networks after host reboots (#11476, fixes #11436).
  • Applied custom Docker options when applications used custom container names, honored selected rollback tags, and respected Compose stop grace periods (#11479, #11480, #11498).
  • Restored custom-format PostgreSQL backups with pg_restore (#11481, fixes #11459).
  • Removed persistent volumes when deleting application previews (#11455, fixes #11441).
  • Made Docker cleanup safe to retry and prevented missing resources from failing deletion (#11463).
  • Fixed registry pushes by updating the helper image's Docker CLI, Compose, and Buildx versions (#11461, fixes #11437).
  • Fixed service log lookup when Docker label values contained commas (#11477, fixes #11454).
  • Allowed system-wide GitHub Apps to work across teams and accepted Coolify CUIDs when updating their private keys through the API (#11453, #11468).
  • Allowed teams with unused private keys or system-wide Git sources to be deleted without removing shared sources (#11499, #11500, fixes #11494).
  • Restored clickable commit links in deployment logs (#11495, fixes #11482).
  • Cleared stale Traefik branch-upgrade warnings after the suggested branch was applied (#11496, fixes #11490).
  • Kept private-key edit dialogs working after multiple keys were deleted (#11497, fixes #11487).
  • Fixed terminal container selection when identical container names existed on different servers.
  • Refreshed service configuration after required environment variables changed.
  • Redacted dotted GitHub tokens from exported logs and prevented wide tables from overflowing their containers.

Improvements

  • Showed a toast with retry guidance when infrastructure-related Livewire requests failed.
  • Distinguished proxy restarts from proxy updates in server status indicators.
  • Made stuck-resource cleanup scalable, scheduled it automatically, and made resource deletion metadata updates atomic.

New Contributors

Full Changelog: v4.3.10...v4.3.11

  •  

Stable Channel Update for Desktop

The Chrome team is delighted to announce the promotion of Chrome 152 to the stable channel for Windows, Mac and Linux. This will roll out over the coming days/weeks.

Chrome 152.0.7977.64 (Linux) 152.0.7977.64/.65 Windows/Mac contains a number of fixes and improvements -- a list of changes is available in the log. Watch out for upcoming Chrome and Chromium blog posts about new features and big efforts delivered in 152.


Security Fixes and Rewards

Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.

This update includes 327 security fixes. Please see the Chrome Security Page for more information.


[$25,000][496807874] Critical CVE-2026-79282: Use after free in ANGLE. Reported by Goodluck on 2026-03-27

[N/A][516427761] Critical CVE-2026-79290: Use after free in Aura. Reported by Google on 2026-05-25

[N/A][516764384] Critical CVE-2026-79054: Use after free in Chromecast. Reported by Google on 2026-05-26

[N/A][516777082] Critical CVE-2026-79121: Improper input validation in Chromecast. Reported by Google on 2026-05-26

[N/A][516988476] Critical CVE-2026-79224: Use after free in Chromecast. Reported by Google on 2026-05-27

[N/A][517518019] Critical CVE-2026-79052: Use after free in Aura. Reported by Google on 2026-05-28

[N/A][518006007] Critical CVE-2026-79150: Use after free in Views. Reported by Google on 2026-05-29

[N/A][522082472] Critical CVE-2026-78935: Use of uninitialized variable in Mobile. Reported by Google on 2026-06-10

[N/A][523704817] Critical CVE-2026-79012: Use after free in Safebrowsing. Reported by Google on 2026-06-13

[N/A][532921800] Critical CVE-2026-79200: Use after free in Aura. Reported by Google on 2026-07-09

[$1,000][532617619] High CVE-2026-78989: Out of bounds read in ANGLE. Reported by Đặng Thế Tuyến on 2026-07-09

[$500][508638064] High CVE-2026-79069: Memory corruption in Tint. Reported by andryskowski.michal on 2026-05-01

[N/A][498885920] High CVE-2026-79175: Type confusion in Accessibility. Reported by Google on 2026-04-02

[N/A][500311587] High CVE-2026-79218: Incorrect authorization in Sandbox. Reported by Google on 2026-04-07

[N/A][501892500] High CVE-2026-79195: Use after free in Script. Reported by Google on 2026-04-12

[N/A][513261751] High CVE-2026-78939: Use after free in Chromecast. Reported by Google on 2026-05-14

[N/A][515470739] High CVE-2026-79194: Use after free in Chromoting. Reported by Google on 2026-05-21

[N/A][515473074] High CVE-2026-79247: Use after free in Chromoting. Reported by Google on 2026-05-21

[N/A][516947491] High CVE-2026-79219: Use after free in Bluetooth. Reported by Google on 2026-05-27

[N/A][517515945] High CVE-2026-79047: Use after free in Views. Reported by Google on 2026-05-28

[N/A][517519352] High CVE-2026-79292: Integer overflow in Chromecast. Reported by Google on 2026-05-28

[N/A][517527943] High CVE-2026-78986: Uninitialized resource in GPU. Reported by Google on 2026-05-28

[N/A][517548647] High CVE-2026-79039: Use after free in Mobile. Reported by Google on 2026-05-28

[N/A][517550232] High CVE-2026-78934: Race condition in ReadAloud. Reported by Google on 2026-05-28

[N/A][517736936] High CVE-2026-79011: UI misrepresentation in Browser. Reported by Google on 2026-05-29

[N/A][517742721] High CVE-2026-78911: Incorrect authorization in USB. Reported by Google on 2026-05-29

[N/A][517959443] High CVE-2026-79257: Use after free in Views. Reported by Google on 2026-05-29

[N/A][521285077] High CVE-2026-79202: Use after free in Chromecast. Reported by Google on 2026-06-08

[N/A][521502218] High CVE-2026-79212: Missing authorization in Passwords. Reported by Google on 2026-06-08

[N/A][521942358] High CVE-2026-79183: Use after free in Accessibility. Reported by Google on 2026-06-09

[N/A][522294538] High CVE-2026-79155: Race condition in FileSystem. Reported by Google on 2026-06-10

[N/A][523095011] High CVE-2026-79093: Incorrect authorization in Paint. Reported by Google on 2026-06-12

[N/A][523266585] High CVE-2026-79019: Out of bounds write in ANGLE. Reported by Google on 2026-06-12

[N/A][523296105] High CVE-2026-79187: Use after free in WebRTC. Reported by Google on 2026-06-12

[N/A][523714535] High CVE-2026-79288: Improper input validation in Autofill. Reported by Google on 2026-06-14

[N/A][523717796] High CVE-2026-79130: Buffer overflow in ANGLE. Reported by Google on 2026-06-14

[N/A][523723064] High CVE-2026-78965: Uninitialized resource in ANGLE. Reported by Google on 2026-06-14

[N/A][523738212] High CVE-2026-79117: Race condition in WebAppInstalls. Reported by Google on 2026-06-14

[N/A][524698525] High CVE-2026-79082: Incorrect authorization in Transactions Platform. Reported by Google on 2026-06-16

[N/A][525683797] High CVE-2026-79111: Improper input validation in Dawn. Reported by Google on 2026-06-19

[N/A][528397177] High CVE-2026-79072: Improper state validation in Performance. Reported by Google on 2026-06-27

[N/A][529509587] High CVE-2026-79142: Buffer overflow in ANGLE. Reported by Google on 2026-06-30

[N/A][529991907] High CVE-2026-78948: Buffer overflow in WebGL. Reported by Google on 2026-07-01

[N/A][532904047] High CVE-2026-78908: Information leak in Canvas. Reported by Google on 2026-07-09

[N/A][532914190] High CVE-2026-78895: Information leak in Paint. Reported by Google on 2026-07-09

[N/A][532988552] High CVE-2026-79043: Out of bounds write in ANGLE. Reported by Google on 2026-07-09

[N/A][534468209] High CVE-2026-79235: Use after free in WebGL. Reported by Google on 2026-07-13

[N/A][534591074] High CVE-2026-79232: Use after free in Aura. Reported by Google on 2026-07-14

[N/A][535379043] High CVE-2026-79118: Uninitialized resource in ANGLE. Reported by Google on 2026-07-16

[TBD][535876894] High CVE-2026-79174: Incorrect authorization in Extensions. Reported by 章鱼哥@aipyaipy.com on 2026-07-17

[N/A][536428615] High CVE-2026-78900: Improper input validation in Media. Reported by Google on 2026-07-19

[N/A][536444272] High CVE-2026-79188: Out of bounds write in ANGLE. Reported by Google on 2026-07-19

[N/A][536505721] High CVE-2026-79189: Out of bounds write in ANGLE. Reported by Google on 2026-07-19

[N/A][536531630] High CVE-2026-79048: Out of bounds write in ANGLE. Reported by Google on 2026-07-19

[N/A][536532605] High CVE-2026-79240: Out of bounds write in ANGLE. Reported by Google on 2026-07-19

[N/A][536568319] High CVE-2026-79014: Race condition in Autofill. Reported by Google on 2026-07-19

[N/A][536606137] High CVE-2026-79198: Use after free in Platform. Reported by Google on 2026-07-19

[N/A][536626343] High CVE-2026-79131: Out of bounds write in ANGLE. Reported by Google on 2026-07-19

[N/A][536636648] High CVE-2026-79149: Use after free in ANGLE. Reported by Google on 2026-07-19

[N/A][536659904] High CVE-2026-79275: Use after free in ANGLE. Reported by Google on 2026-07-20

[N/A][536681676] High CVE-2026-79138: Out of bounds write in ANGLE. Reported by Google on 2026-07-20

[N/A][537109028] High CVE-2026-79026: Use after free in Extensions. Reported by Google on 2026-07-21

[TBD][537233963] High CVE-2026-79027: Use after free in WebRTC. Reported by Mozilla on 2026-07-21

[N/A][537835609] High CVE-2026-78904: Type confusion in ANGLE. Reported by Google on 2026-07-22

[TBD][540430406] High CVE-2026-78899: Use after free in V8. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern) on 2026-07-29

[N/A][540870921] High CVE-2026-78954: Incorrect authorization in Extensions. Reported by Google on 2026-07-30

[TBD][543707066] High CVE-2026-79274: Information leak in GPU. Reported by weihengqiuu on 2026-08-07

[TBD][545767601] High CVE-2026-78938: Type confusion in V8. Reported by Zhenpeng (Leo) Lin at depthfirst on 2026-08-12

[TBD][545820931] High CVE-2026-78952: Out of bounds write in Crashpad. Reported by Brendan Dolan-Gavitt, XBOW on 2026-08-13

[TBD][546670199] High CVE-2026-79236: Type confusion in V8. Reported by Zhenpeng (Leo) Lin on 2026-08-14

[TBD][548340637] High CVE-2026-79078: Use after free in FedCM. Reported by m0omo0d on 2026-08-18

[$8,000][495021566] Medium CVE-2026-79209: Type confusion in Animation. Reported by ochko on 2026-03-22

[$2,000][40057398] Medium CVE-2026-79030: Observable discrepancy in Autofill. Reported by Young Min Kim (@ylemkimon), CompSec Lab at Seoul National

University on 2021-09-25

[$1,000][536913431] Medium CVE-2026-79216: Buffer overflow in Blink. Reported by Found by XBOW and triaged by Andrés Luksenberg on 2026-07-20

[N/A][495579602] Medium CVE-2026-79007: Uninitialized resource in GPU. Reported by Google on 2026-03-24

[N/A][495998981] Medium CVE-2026-78893: Information leak in QUIC. Reported by Google on 2026-03-25

[N/A][496195129] Medium CVE-2026-79222: Incorrect authorization in CustomTabs. Reported by Google on 2026-03-25

[N/A][496292729] Medium CVE-2026-79071: Race condition in GPU. Reported by Google on 2026-03-25

[N/A][496395158] Medium CVE-2026-79076: Improper input validation in Sync. Reported by Google on 2026-03-26

[N/A][496401361] Medium CVE-2026-79088: Incorrect authorization in FileSystem. Reported by Google on 2026-03-26

[N/A][497017869] Medium CVE-2026-79104: Missing authorization in Sensor. Reported by Google on 2026-03-27

[N/A][497095313] Medium CVE-2026-79044: Missing authorization in WebAppInstalls. Reported by Google on 2026-03-28

[N/A][497205529] Medium CVE-2026-78958: Uninitialized resource in Skia. Reported by Google on 2026-03-28

[N/A][497269030] Medium CVE-2026-78961: Incorrect authorization in Core. Reported by Google on 2026-03-28

[N/A][497338168] Medium CVE-2026-79262: Incorrect authorization in Network. Reported by Google on 2026-03-29

[N/A][497456156] Medium CVE-2026-79106: Improper input validation in Input. Reported by Google on 2026-03-29

[N/A][497538341] Medium CVE-2026-79176: UI misrepresentation in Extensions. Reported by Google on 2026-03-29

[N/A][497637694] Medium CVE-2026-78966: Externally controlled reference in QUIC. Reported by Google on 2026-03-30

[N/A][497646947] Medium CVE-2026-79186: Incorrect authorization in Network. Reported by Google on 2026-03-30

[N/A][497839983] Medium CVE-2026-79267: Race condition in Workers. Reported by Google on 2026-03-30

[N/A][497854976] Medium CVE-2026-79016: Observable discrepancy in SVG. Reported by Google on 2026-03-30

[N/A][497869284] Medium CVE-2026-79010: Operation on a resource after expiration or release in Network. Reported by Google on 2026-03-30

[N/A][497940451] Medium CVE-2026-79286: Missing authorization in CustomTabs. Reported by Google on 2026-03-30

[N/A][497948894] Medium CVE-2026-78945: Use after free in Views. Reported by Google on 2026-03-30

[N/A][497957278] Medium CVE-2026-78999: Improper privilege management in Navigation. Reported by Google on 2026-03-30

[N/A][498327743] Medium CVE-2026-78941: Information leak in Core. Reported by Google on 2026-03-31

[N/A][498328139] Medium CVE-2026-79032: Improper input validation in Network. Reported by Google on 2026-03-31

[N/A][498367544] Medium CVE-2026-79109: Improper input validation in Printing. Reported by Google on 2026-04-01

[N/A][499007248] Medium CVE-2026-79256: Externally controlled reference in WebView. Reported by Google on 2026-04-02

[N/A][499068536] Medium CVE-2026-79237: Incorrect authorization in Navigation. Reported by Google on 2026-04-02

[N/A][499423269] Medium CVE-2026-78898: Incorrect authorization in Downloads. Reported by Google on 2026-04-04

[N/A][500038021] Medium CVE-2026-78985: Incorrect reference resolution in FileSystem. Reported by Google on 2026-04-06

[N/A][500492844] Medium CVE-2026-79028: Observable discrepancy in Network. Reported by Google on 2026-04-08

[N/A][501331457] Medium CVE-2026-79210: Use after free in Audio. Reported by Google on 2026-04-10

[N/A][501437087] Medium CVE-2026-79046: Race condition in Permissions. Reported by Google on 2026-04-10

[N/A][501572758] Medium CVE-2026-79129: Use after free in Sessions. Reported by Google on 2026-04-11

[N/A][501590191] Medium CVE-2026-78937: Use after free in Search. Reported by Google on 2026-04-11

[N/A][501594511] Medium CVE-2026-78987: Information leak in Canvas. Reported by Google on 2026-04-11

[N/A][501604761] Medium CVE-2026-78990: Use after free in Compositing. Reported by Google on 2026-04-11

[N/A][501637242] Medium CVE-2026-78909: Use after free in Views. Reported by Google on 2026-04-11

[N/A][501661601] Medium CVE-2026-79271: Information leak in DOM. Reported by Google on 2026-04-11

[N/A][501759192] Medium CVE-2026-79144: Information leak in Skia. Reported by Google on 2026-04-11

[N/A][501799770] Medium CVE-2026-79065: Improper input validation in Network. Reported by Google on 2026-04-12

[N/A][502082953] Medium CVE-2026-79192: Improper input validation in Variations. Reported by Google on 2026-04-13

[N/A][502101200] Medium CVE-2026-79140: Use after free in Views. Reported by Google on 2026-04-13

[N/A][502109333] Medium CVE-2026-79128: Use after free in Views. Reported by Google on 2026-04-13

[N/A][502139081] Medium CVE-2026-78942: Incorrect reference resolution in Loader. Reported by Google on 2026-04-13

[N/A][502232151] Medium CVE-2026-79116: Missing authorization in Viz. Reported by Google on 2026-04-13

[N/A][502344135] Medium CVE-2026-79006: Protection mechanism failure in HttpsUpgrades. Reported by Google on 2026-04-14

[N/A][502488051] Medium CVE-2026-79095: Information leak in Payments. Reported by Google on 2026-04-14

[N/A][502805441] Medium CVE-2026-79084: Inadequate encryption strength in Notifications. Reported by Google on 2026-04-15

[N/A][502888857] Medium CVE-2026-78991: Race condition in WebProtect. Reported by Google on 2026-04-15

[N/A][502918844] Medium CVE-2026-79248: Incorrect authorization in Input. Reported by Google on 2026-04-15

[TBD][503013378] Medium CVE-2026-78891: Buffer overflow in WebRTC. Reported by ngrunbaum on 2026-04-15

[N/A][503472696] Medium CVE-2026-79031: Improper resource exposure in Preload. Reported by Google on 2026-04-16

[N/A][503585863] Medium CVE-2026-79110: Missing authorization in Preload. Reported by Google on 2026-04-17

[N/A][503624894] Medium CVE-2026-79136: Incorrect authorization in ServiceWorker. Reported by Google on 2026-04-17

[N/A][503847023] Medium CVE-2026-78907: Incorrect authorization in WebProtect. Reported by Google on 2026-04-17

[N/A][504226770] Medium CVE-2026-79087: Injection in Chrome Tabs. Reported by Google on 2026-04-19

[N/A][504356442] Medium CVE-2026-79231: Buffer overflow in Media. Reported by Google on 2026-04-19

[N/A][504633668] Medium CVE-2026-78969: Uninitialized resource in Video. Reported by Google on 2026-04-20

[N/A][505951430] Medium CVE-2026-79137: Incorrect authorization in Extensions. Reported by Google on 2026-04-24

[N/A][505967344] Medium CVE-2026-79057: Race condition in Start. Reported by Google on 2026-04-24

[N/A][505991181] Medium CVE-2026-78894: Race condition in Payments. Reported by Google on 2026-04-24

[N/A][507483993] Medium CVE-2026-79264: Incorrect reference resolution in Preload. Reported by Google on 2026-04-28

[N/A][511260796] Medium CVE-2026-78910: Buffer overflow in V8. Reported by Google on 2026-05-08

[N/A][511736672] Medium CVE-2026-79066: Improper input validation in Navigation. Reported by Google on 2026-05-10

[N/A][511794959] Medium CVE-2026-79255: Improper input validation in WebRTC. Reported by Google on 2026-05-10

[N/A][511804361] Medium CVE-2026-79086: Missing authorization in CustomTabs. Reported by Google on 2026-05-10

[N/A][511806043] Medium CVE-2026-79038: Incorrect authorization in WebProtect. Reported by Google on 2026-05-10

[N/A][511819962] Medium CVE-2026-78940: Improper initialization in Network. Reported by Google on 2026-05-10

[N/A][511822878] Medium CVE-2026-79107: Incorrect authorization in TabGroups. Reported by Google on 2026-05-10

[N/A][512971896] Medium CVE-2026-79120: Uninitialized resource in ANGLE. Reported by Google on 2026-05-13

[N/A][513048462] Medium CVE-2026-79270: Uninitialized resource in ANGLE. Reported by Google on 2026-05-14

[N/A][513049445] Medium CVE-2026-79067: Missing authorization in Network. Reported by Google on 2026-05-14

[N/A][513119757] Medium CVE-2026-79213: Incorrect authorization in WebAppInstalls. Reported by Google on 2026-05-14

[N/A][513192145] Medium CVE-2026-78943: Improper input validation in Editing. Reported by Google on 2026-05-14

[N/A][513222422] Medium CVE-2026-79259: Improper input validation in Safebrowsing. Reported by Google on 2026-05-14

[N/A][513287677] Medium CVE-2026-79208: Missing authorization in HTTP2. Reported by Google on 2026-05-14

[N/A][513392351] Medium CVE-2026-79251: Improper input validation in Network. Reported by Google on 2026-05-15

[N/A][513607252] Medium CVE-2026-79226: Improper privilege management in Regional Capabilities. Reported by Google on 2026-05-15

[N/A][513608317] Medium CVE-2026-79042: Missing authorization in Payments. Reported by Google on 2026-05-15

[N/A][513608831] Medium CVE-2026-79122: Information leak in SignIn. Reported by Google on 2026-05-15

[N/A][513719741] Medium CVE-2026-79199: Incorrect authorization in Network. Reported by Google on 2026-05-16

[N/A][513737209] Medium CVE-2026-79013: Improper input validation in Sync. Reported by Google on 2026-05-16

[N/A][513745793] Medium CVE-2026-79074: Information leak in Network. Reported by Google on 2026-05-16

[N/A][513760788] Medium CVE-2026-79215: Integer overflow in WebGL. Reported by Google on 2026-05-16

[N/A][513786555] Medium CVE-2026-79049: Incorrect reference resolution in Passwords. Reported by Google on 2026-05-16

[N/A][513834155] Medium CVE-2026-79132: Improper input validation in Input. Reported by Google on 2026-05-16

[N/A][513836495] Medium CVE-2026-79201: Improper access control in Workers. Reported by Google on 2026-05-16

[N/A][513841856] Medium CVE-2026-79051: Incorrect authorization in Loader. Reported by Google on 2026-05-16

[N/A][513850062] Medium CVE-2026-79053: Missing authorization in Lighthouse. Reported by Google on 2026-05-16

[N/A][513918923] Medium CVE-2026-79285: Uninitialized resource in ANGLE. Reported by Google on 2026-05-17

[N/A][513923164] Medium CVE-2026-78906: Race condition in ANGLE. Reported by Google on 2026-05-17

[N/A][514006744] Medium CVE-2026-79250: UI misrepresentation in Navigation. Reported by Google on 2026-05-17

[N/A][514017820] Medium CVE-2026-79020: Out of bounds read in Skia. Reported by Google on 2026-05-17

[N/A][514055709] Medium CVE-2026-79217: Incorrect authorization in Mobile. Reported by Google on 2026-05-17

[N/A][514069975] Medium CVE-2026-79204: UI misrepresentation in Input. Reported by Google on 2026-05-17

[N/A][514078852] Medium CVE-2026-78912: UI misrepresentation in Browser. Reported by Google on 2026-05-17

[N/A][514439436] Medium CVE-2026-78955: Observable discrepancy in PerformanceAPIs. Reported by Google on 2026-05-18

[N/A][514454739] Medium CVE-2026-79143: Incorrect authorization in FileSystem. Reported by Google on 2026-05-19

[N/A][514508415] Medium CVE-2026-79241: Out of bounds read in GPU. Reported by Google on 2026-05-19

[N/A][514529599] Medium CVE-2026-78967: Missing authorization in BFCache. Reported by Google on 2026-05-19

[N/A][515477007] Medium CVE-2026-79214: Improper input validation in Preload. Reported by Google on 2026-05-21

[N/A][516398679] Medium CVE-2026-79228: Incorrect authorization in SiteIsolation. Reported by Google on 2026-05-25

[N/A][516665605] Medium CVE-2026-78953: Missing authorization in SiteIsolation. Reported by Google on 2026-05-26

[N/A][516824665] Medium CVE-2026-79229: Uninitialized resource in ANGLE. Reported by Google on 2026-05-26

[N/A][516899248] Medium CVE-2026-79002: Incorrect authorization in SiteIsolation. Reported by Google on 2026-05-26

[N/A][516921259] Medium CVE-2026-79272: Improper input validation in FindInPage. Reported by Google on 2026-05-27

[N/A][517045394] Medium CVE-2026-79127: Out of bounds write in ANGLE. Reported by Google on 2026-05-27

[N/A][517074167] Medium CVE-2026-79151: Improper input validation in Safebrowsing. Reported by Google on 2026-05-27

[N/A][517095594] Medium CVE-2026-78936: Observable discrepancy in CustomTabs. Reported by Google on 2026-05-27

[N/A][517245017] Medium CVE-2026-78905: Type confusion in ANGLE. Reported by Google on 2026-05-27

[N/A][517364411] Medium CVE-2026-79050: Incorrect authorization in Network. Reported by Google on 2026-05-28

[N/A][517382613] Medium CVE-2026-79008: Improper input validation in GPU. Reported by Google on 2026-05-28

[N/A][517398863] Medium CVE-2026-78975: Incorrect authorization in DOM. Reported by Google on 2026-05-28

[N/A][517404644] Medium CVE-2026-79287: Observable discrepancy in Forms. Reported by Google on 2026-05-28

[N/A][517467117] Medium CVE-2026-79094: Race condition in Workers. Reported by Google on 2026-05-28

[N/A][517487890] Medium CVE-2026-79173: UI misrepresentation in WebAppInstalls. Reported by Google on 2026-05-28

[N/A][517550421] Medium CVE-2026-78976: Improper input validation in StorageAccessAPI. Reported by Google on 2026-05-28

[N/A][517580738] Medium CVE-2026-79276: Improper privilege management in FileSystem. Reported by Google on 2026-05-28

[N/A][517606780] Medium CVE-2026-79191: Incorrect authorization in SiteIsolation. Reported by Google on 2026-05-28

[N/A][517608454] Medium CVE-2026-79099: Missing authorization in Network. Reported by Google on 2026-05-28

[N/A][517634590] Medium CVE-2026-79024: Information leak in ServiceWorker. Reported by Google on 2026-05-28

[N/A][517655953] Medium CVE-2026-79193: Information leak in Canvas. Reported by Google on 2026-05-28

[N/A][517697155] Medium CVE-2026-79242: Observable discrepancy in HTML. Reported by Google on 2026-05-29

[N/A][517719358] Medium CVE-2026-79180: UI misrepresentation in CustomTabs. Reported by Google on 2026-05-29

[N/A][517746687] Medium CVE-2026-79293: Information leak in Animation. Reported by Google on 2026-05-29

[N/A][517761566] Medium CVE-2026-79023: Incorrect authorization in Editing. Reported by Google on 2026-05-29

[N/A][517772510] Medium CVE-2026-79146: Information leak in CustomTabs. Reported by Google on 2026-05-29

[N/A][517774971] Medium CVE-2026-79238: Incorrect authorization in ServiceWorker. Reported by Google on 2026-05-29

[N/A][517910756] Medium CVE-2026-78949: Observable discrepancy in CustomTabs. Reported by Google on 2026-05-29

[N/A][518023156] Medium CVE-2026-79291: Information leak in CSS. Reported by Google on 2026-05-29

[N/A][518035396] Medium CVE-2026-79283: UI misrepresentation in Geometry. Reported by Google on 2026-05-29

[N/A][518053893] Medium CVE-2026-78892: Incorrect authorization in Chromoting. Reported by Google on 2026-05-30

[N/A][518062961] Medium CVE-2026-79070: Incorrect reference resolution in Cache. Reported by Google on 2026-05-30

[N/A][518065628] Medium CVE-2026-79205: Incorrect authorization in Network. Reported by Google on 2026-05-30

[N/A][518078552] Medium CVE-2026-78903: Incomplete cleanup in SiteIsolation. Reported by Google on 2026-05-30

[N/A][518084889] Medium CVE-2026-78959: Improper handling of case sensitivity in FileSystem. Reported by Google on 2026-05-30

[N/A][518094442] Medium CVE-2026-79234: Injection in CSS. Reported by Google on 2026-05-30

[N/A][519369088] Medium CVE-2026-78983: Use after free in Views. Reported by Google on 2026-06-03

[N/A][519984038] Medium CVE-2026-79083: Improper enforcement of behavioral workflow in Media. Reported by Google on 2026-06-04

[TBD][520052954] Medium CVE-2026-78944: Use after free in DevTools. Reported by yupyon.itome on 2026-06-05

[N/A][520117546] Medium CVE-2026-79178: Incorrect authorization in Web Authentication (Passkeys & Security Keys). Reported by Google on 2026-06-04

[N/A][520121111] Medium CVE-2026-79059: Information leak in BFCache. Reported by Google on 2026-06-04

[N/A][520179360] Medium CVE-2026-79245: Use after free in UI. Reported by Google on 2026-06-05

[N/A][520464738] Medium CVE-2026-78978: Out of bounds read in ANGLE. Reported by Google on 2026-06-05

[N/A][520481800] Medium CVE-2026-79103: Incorrect reference resolution in Speech. Reported by Google on 2026-06-05

[N/A][520492291] Medium CVE-2026-79154: Missing authorization in DevTools. Reported by Google on 2026-06-05

[N/A][520504922] Medium CVE-2026-79230: Improper input validation in ANGLE. Reported by Google on 2026-06-05

[N/A][520516462] Medium CVE-2026-79068: Improper resource exposure in StreamsAPI. Reported by Google on 2026-06-05

[N/A][520542088] Medium CVE-2026-79269: Uninitialized resource in ANGLE. Reported by Google on 2026-06-05

[N/A][522077127] Medium CVE-2026-79085: Missing authorization in Network. Reported by Google on 2026-06-10

[N/A][522351802] Medium CVE-2026-79134: Incorrect authorization in GetUserMedia. Reported by Google on 2026-06-10

[N/A][522550059] Medium CVE-2026-79064: Use after free in Network. Reported by Google on 2026-06-11

[N/A][522791354] Medium CVE-2026-79003: Incorrect authorization in Device. Reported by Google on 2026-06-11

[N/A][522823211] Medium CVE-2026-79220: Information leak in Network. Reported by Google on 2026-06-11

[N/A][522957054] Medium CVE-2026-78951: Use after free in ServiceWorker. Reported by Google on 2026-06-11

[N/A][523232966] Medium CVE-2026-79249: Code injection in Bisection. Reported by Google on 2026-06-12

[N/A][523557855] Medium CVE-2026-79091: Use after free in Bluetooth. Reported by Google on 2026-06-13

[N/A][523661149] Medium CVE-2026-79265: Incomplete cleanup in GetUserMedia. Reported by Google on 2026-06-13

[N/A][523716748] Medium CVE-2026-78913: Use after free in Chromoting. Reported by Google on 2026-06-14

[N/A][524418836] Medium CVE-2026-79258: Incorrect authorization in WebXR. Reported by Google on 2026-06-16

[TBD][524520965] Medium CVE-2026-79211: Incorrect authorization in USB. Reported by hongan on 2026-06-16

[N/A][524541667] Medium CVE-2026-79252: Information leak in ServiceWorker. Reported by Google on 2026-06-16

[N/A][524822825] Medium CVE-2026-78962: Uninitialized resource in WebXR. Reported by Google on 2026-06-17

[N/A][525686865] Medium CVE-2026-78901: Race condition in V8. Reported by Google on 2026-06-19

[N/A][525689847] Medium CVE-2026-79097: Use after free in V8. Reported by Google on 2026-06-19

[N/A][532162132] Medium CVE-2026-79227: Type confusion in DevTools. Reported by Google on 2026-07-07

[N/A][532182486] Medium CVE-2026-79203: Improper input validation in DevTools. Reported by Google on 2026-07-07

[N/A][532914769] Medium CVE-2026-79033: Insufficient control flow management in DevTools. Reported by Google on 2026-07-09

[N/A][532917452] Medium CVE-2026-79139: Improper input validation in Media. Reported by Google on 2026-07-09

[N/A][532923954] Medium CVE-2026-79221: Uninitialized resource in Dawn. Reported by Google on 2026-07-09

[N/A][532957785] Medium CVE-2026-79034: Information leak in CORS. Reported by Google on 2026-07-09

[N/A][533093250] Medium CVE-2026-79075: Information leak in Geolocation. Reported by Google on 2026-07-09

[TBD][533917984] Medium CVE-2026-78960: Information leak in Extensions. Reported by Oran Simhony from Palo Alto Networks on 2026-07-12

[N/A][535374213] Medium CVE-2026-78984: Uninitialized resource in GPU. Reported by Google on 2026-07-16

[N/A][536428842] Medium CVE-2026-78963: Improper input validation in Media. Reported by Google on 2026-07-19

[N/A][536428988] Medium CVE-2026-79004: Out of bounds read in Media. Reported by Google on 2026-07-19

[N/A][536444242] Medium CVE-2026-79182: Improper input validation in Media. Reported by Google on 2026-07-19

[TBD][536526176] Medium CVE-2026-79185: Information leak in DOM. Reported by avlidienbrunn on 2026-07-19

[N/A][536662911] Medium CVE-2026-79073: Improper state validation in Parser. Reported by Google on 2026-07-20

[N/A][537145191] Medium CVE-2026-79266: Use after free in DevTools. Reported by Google on 2026-07-21

[N/A][537846307] Medium CVE-2026-79025: Improper input validation in Workers. Reported by Google on 2026-07-22

[TBD][538969297] Medium CVE-2026-79141: Incorrect authorization in Browser. Reported by M. Fauzan Wijaya (Gh05t666nero) on 2026-07-25

[$1,000][503048520] Low CVE-2026-78974: UI misrepresentation in Linux Toolkit Theming. Reported by Francesco Topol on 2026-04-16

[N/A][497232609] Low CVE-2026-79055: Information leak in Sharing. Reported by Google on 2026-03-28

[N/A][497256260] Low CVE-2026-79263: Race condition in Extensions. Reported by Google on 2026-03-28

[N/A][497493136] Low CVE-2026-79124: Information leak in Intents. Reported by Google on 2026-03-29

[N/A][497499482] Low CVE-2026-79184: Missing authorization in Preload. Reported by Google on 2026-03-29

[N/A][497876969] Low CVE-2026-79289: Improper control of a resource through its lifetime in Workers. Reported by Google on 2026-03-30

[N/A][500484520] Low CVE-2026-79001: Information leak in Bluetooth. Reported by Google on 2026-04-07

[N/A][501416859] Low CVE-2026-79077: Incorrect authorization in WebProtect. Reported by Google on 2026-04-10

[TBD][501881082] Low CVE-2026-78950: Integer overflow in WebRTC. Reported by Ashutosh on 2026-04-12

[N/A][502252964] Low CVE-2026-79196: Race condition in Editing. Reported by Google on 2026-04-13

[N/A][502514083] Low CVE-2026-79000: Improper input validation in DeviceBoundSessionCredentials. Reported by Google on 2026-04-14

[N/A][503720291] Low CVE-2026-78979: Race condition in Core. Reported by Google on 2026-04-17

[N/A][506539337] Low CVE-2026-79181: Observable discrepancy in Glic. Reported by Google on 2026-04-26

[N/A][513172858] Low CVE-2026-79190: Incorrect authorization in Extensions. Reported by Google on 2026-05-14

[N/A][513361380] Low CVE-2026-79206: Out of bounds read in FileSystem. Reported by Google on 2026-05-15

[N/A][513486883] Low CVE-2026-78897: Missing authorization in BrowserTag. Reported by Google on 2026-05-15

[N/A][513688690] Low CVE-2026-79119: Use after free in PDF. Reported by Google on 2026-05-15

[N/A][513792983] Low CVE-2026-79089: Race condition in Transactions Platform. Reported by Google on 2026-05-16

[N/A][513969378] Low CVE-2026-79147: Information leak in Skia. Reported by Google on 2026-05-17

[N/A][514010111] Low CVE-2026-79098: UI misrepresentation in PermissionElement. Reported by Google on 2026-05-17

[N/A][514038302] Low CVE-2026-79022: UI misrepresentation in Transactions Platform. Reported by Google on 2026-05-17

[N/A][514061923] Low CVE-2026-79233: UI misrepresentation in CustomTabs. Reported by Google on 2026-05-17

[N/A][514408247] Low CVE-2026-79261: Incorrect authorization in Controls. Reported by Google on 2026-05-18

[N/A][516864349] Low CVE-2026-78977: Uninitialized resource in GPU. Reported by Google on 2026-05-26

[N/A][516950646] Low CVE-2026-79040: Uninitialized resource in GPU. Reported by Google on 2026-05-27

[N/A][517167020] Low CVE-2026-79273: Incorrect reference resolution in WebView. Reported by Google on 2026-05-27

[TBD][517394060] Low CVE-2026-79243: Improper input validation in ReadingList. Reported by Orange Tsai (@orange_8361) of DEVCORE Research Team on 2026-05-28

[TBD][517395590] Low CVE-2026-79123: Improper input validation in NTP Footer. Reported by Orange Tsai (@orange_8361) of DEVCORE Research Team on 2026-05-28

[N/A][517540292] Low CVE-2026-79005: Incorrect authorization in StorageAccessAPI. Reported by Google on 2026-05-28

[N/A][517673944] Low CVE-2026-79090: Improper privilege management in Actor. Reported by Google on 2026-05-29

[N/A][517718241] Low CVE-2026-78946: Incorrect authorization in Select. Reported by Google on 2026-05-29

[N/A][518125889] Low CVE-2026-78968: Missing authorization in Core. Reported by Google on 2026-05-30

[N/A][518249083] Low CVE-2026-79041: Missing authorization in Browser. Reported by Google on 2026-05-30

[N/A][519210950] Low CVE-2026-79284: UI misrepresentation in Core. Reported by Google on 2026-06-02

[N/A][519229463] Low CVE-2026-78896: Information leak in StorageAccessAPI. Reported by Google on 2026-06-02

[N/A][519242511] Low CVE-2026-79058: Missing authorization in Passwords. Reported by Google on 2026-06-02

[N/A][519246298] Low CVE-2026-79009: UI misrepresentation in UI. Reported by Google on 2026-06-02

[N/A][519254827] Low CVE-2026-79060: Incorrect authorization in StorageAccessAPI. Reported by Google on 2026-06-02

[N/A][520002854] Low CVE-2026-79177: Incorrect authorization in Media. Reported by Google on 2026-06-04

[N/A][520016142] Low CVE-2026-78956: Type confusion in V8. Reported by Google on 2026-06-04

[TBD][520781436] Low CVE-2026-79239: Out of bounds read in Tint. Reported by Michal Andryskowski, Imperial College London on 2026-06-07

[N/A][522291712] Low CVE-2026-79015: Improper input validation in ServiceWorker. Reported by Google on 2026-06-10

[N/A][522304549] Low CVE-2026-79108: UI misrepresentation in Web Authentication (Passkeys & Security Keys). Reported by Google on 2026-06-10

[N/A][522418913] Low CVE-2026-79056: Use after free in ServiceWorker. Reported by Google on 2026-06-10

[N/A][522803735] Low CVE-2026-79018: Information leak in FoldableAPIs. Reported by Google on 2026-06-11

[N/A][523237735] Low CVE-2026-78980: Improper input validation in ReaderMode. Reported by Google on 2026-06-12

[N/A][523313378] Low CVE-2026-78947: Incomplete cleanup in Chromium. Reported by Microsoft Edge on 2026-06-12

[N/A][523572877] Low CVE-2026-79244: Use after free in Animation. Reported by Google on 2026-06-13

[TBD][524864599] Low CVE-2026-79112: Out of bounds read in Skia. Reported by Quan Huynh x Amaterasu on 2026-06-17

[N/A][525311654] Low CVE-2026-79246: Information leak in DataTransfer. Reported by Google on 2026-06-18

[TBD][530816571] Low CVE-2026-79223: Integer overflow in Chromium. Reported by Youngjin Ju on 2026-07-03

[N/A][531245718] Low CVE-2026-79045: Type confusion in V8. Reported by Google on 2026-07-04

[N/A][531297707] Low CVE-2026-79197: Use after free in V8. Reported by Google on 2026-07-05

[N/A][532303080] Low CVE-2026-79148: Off-by-one error in DevTools. Reported by Google on 2026-07-08

[N/A][533001362] Low CVE-2026-79125: Information leak in XR. Reported by Google on 2026-07-09

[N/A][533014006] Low CVE-2026-79207: Information leak in Passwords. Reported by Google on 2026-07-09

[N/A][533021205] Low CVE-2026-79017: Race condition in Extensions. Reported by Google on 2026-07-09

[N/A][533046298] Low CVE-2026-79105: Improper input validation in Mobile. Reported by Google on 2026-07-09

[N/A][533059149] Low CVE-2026-79225: Incorrect authorization in Browser. Reported by Google on 2026-07-09

[N/A][533060125] Low CVE-2026-79021: Missing authorization in InterestGroups. Reported by Google on 2026-07-09

[N/A][533075126] Low CVE-2026-79133: Incorrect authorization in Forms. Reported by Google on 2026-07-09

[N/A][533079345] Low CVE-2026-79179: Incorrect authorization in DOM. Reported by Google on 2026-07-09

[N/A][533083384] Low CVE-2026-79152: Incorrect authorization in CustomTabs. Reported by Google on 2026-07-09

[N/A][533121405] Low CVE-2026-78981: Information leak in Mobile. Reported by Google on 2026-07-09

[N/A][533123348] Low CVE-2026-78957: Information leak in Mobile. Reported by Google on 2026-07-09

[N/A][533408915] Low CVE-2026-79126: Incorrect provision of specified functionality in Proxy. Reported by Google on 2026-07-10

[N/A][533418127] Low CVE-2026-78915: Race condition in Enterprise. Reported by Google on 2026-07-10

[N/A][533511921] Low CVE-2026-79253: Improper input validation in Network. Reported by Google on 2026-07-10

[N/A][533511967] Low CVE-2026-79260: Improper input validation in Cookies. Reported by Google on 2026-07-10

[N/A][534556413] Low CVE-2026-79254: Incorrect reference resolution in CustomTabs. Reported by Google on 2026-07-14

[N/A][536166543] Low CVE-2026-78914: Uninitialized resource in Skia. Reported by Google on 2026-07-18

[N/A][539341100] Low CVE-2026-78964: Use after free in Sync. Reported by Google on 2026-07-27


We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.


Many of our security bugs are detected using AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, or AFL.


Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.


Srinivas Sista

Google Chrome

  •  

v1.9.0 - Fullscreen Email & Pro Split-Screen, Mobile Swipe Actions, and Configurable List Ordering

1.9.0 (2026-08-25)

Thank you for your donations:

One-time

Monthly

Features

  • Mail: Fullscreen email view in the standard interface
  • Mail: Drag a mail onto a new browser tab to open it fullscreen
  • Mail: Configurable message-list ordering (#718)
  • Mail: Search suggestions with recent searches and contact autocomplete (#845)
  • Mail: Render plain-text emails in the app font by default, with a monospace option (#830)
  • Mail: Pull-to-refresh indicator while dragging the list down (#826)
  • Mail: Redesigned unread favicon badge — a compact keyline badge
  • Mobile: Swipe message rows left or right for quick actions — archive, delete, toggle read, toggle star, or spam, configurable per direction, RTL-aware
  • Pro: Reworked split-screen shell with per-pane tab strips, drag & drop between panes, and pane-scoped overlays
  • Pro: Folder tabs via drag & drop
  • Pro: The address bar follows the focused tab, and deep links are delivered live to already-mounted surfaces
  • Composer: Real byte progress for attachment uploads, stock and plugin-offloaded; cancel now aborts the transfer itself
  • Calendar: Moving an event's start moves the end with it, keeping the event's length
  • Contacts: Trusted Senders address book enabled by default on contacts-capable accounts
  • Settings: Custom time zone setting that overrides browser detection (#755)
  • Login: Server dropdown on the OAuth-only login screen (#799)
  • Push: New-mail notifications grouped per account with a "+N more messages" line instead of one notification per message
  • Push: Per-device revoke for push subscriptions (#841)
  • Admin: Configurable Stalwart admin access to the dashboard (#870)
  • Admin: Push relay picked from an admin-defined list instead of a free URL field
  • Branding: OpenGraph/Twitter link previews with a generated card image
  • Performance: Halved time-to-mail-list — lazy locale catalogs, code-split viewer and composer, shorter auth waterfall, boot snapshot
  • i18n: Mongolian translation
  • Plugins: jmap.uploadBlob
  • Plugins: onBeforeComposeOpenToReply and sibling hooks let a plugin edit an email before it populates the composer for reply or forward
  • Plugins: getPublicKeyFromWKD
  • Plugins: Privileged plugins can fetch a byte range of a blob
  • Plugins: progressFileId on api.http.post so an offloaded upload reports byte progress to the composer chip
  • Plugins: isActive on AccountResponse
  • Plugins: Label settings and label reordering exposed to extensions
  • Plugins: JMAP keyword helpers and gateway keywords exposed to extensions
  • Plugins: Mailbox refresh hook
  • Dev: AddressBook/set in the dev mock JMAP server

Changes

  • Plugins: The PRF getOrCreate flow is split into separate get and create steps for better authenticator compatibility (#851)
  • Dependencies: Next 16.3.3, pdfjs-dist 6.2.108, DOMPurify 3.4.14 (npm audit)

Fixes

  • Send: Route scheduled sends to the account that owns the submission — mail scheduled from a shared address can now be listed, cancelled, and rescheduled instead of going out silently (#874)
  • Send: Split recipient lists whose angle brackets never close without dropping recipients
  • Send: generateMessageId crashed on insecure origins (crypto.randomUUID undefined), failing the send after the draft save
  • Composer: Keep attachments when re-opening a draft, also in the Pro draft tab, and destroy old draft versions only after a successful create or send (#849)
  • Composer: Keep the signature in saved drafts and embed it into re-opened drafts (#848)
  • Composer: Double-click unlocks the embedded signature for editing
  • Composer: Keep already written text when applying a template (#540)
  • Composer: Preselect the shared folder's identity for new messages
  • Composer: Namespace all accounts consistently in the Pro composer identity list
  • Composer: Opening a mailto: link runs the unsaved-draft dialog instead of replacing the draft outright
  • Composer: Keep the fresh-compose tab title clear of the selected email subject
  • Composer: Clear the viewer when sending destroys the displayed draft
  • Reply: Honour an external Reply-To even on a self-sent message
  • Mail: Flip $junk/$notjunk keywords on spam and not-spam (#850)
  • Mail: Remove keywords with null rather than false in Email/set, per RFC 8620
  • Mail: Escape the JSON Pointer in keyword patches so nested tags like work/clients patch the right keyword
  • Mail: Route keyword writes — tags, pins, flags — to the selected shared account so they persist
  • Mail: Route shared-folder management to the owner account, scoped to one server
  • Mail: Open the right conversations in a shared mailbox (#814)
  • Mail: Route multi-account email lookups and invitation parsing by source account (#847), and parse invitations in directly viewed shared folders against the folder owner (#867)
  • Mail: Folders containing a system folder name no longer disappear from the sidebar (#771)
  • Mail: Folder drag & drop can move folders into other parents (#855)
  • Mail: Keep the folder tree when a refresh burst hits maxConcurrentRequests (#780)
  • Mail: Stop All-Mail and cross-account views emptying on delete, star, or mark-read (#791)
  • Mail: Keep just-read or unstarred mail in the open Unread/Starred view
  • Mail: Search folder filter defaults to all folders and persists (#788)
  • Mail: Fixed-width read/unread toolbar button so buttons don't jump when a message opens (#864)
  • Mail: Transparent hover-action background on tagged rows
  • Mail: Enforce the external media preference on plugin-rendered bodies (#797)
  • Mail: Apply the data: URI allowlist to media tags and srcset candidates too
  • Mail: Make label reordering atomic
  • Mail: Pass PDF bytes to pdf.js instead of fetching the blob: URL that CSP connect-src blocks (#871)
  • Mail: Include email templates in cross-device settings sync (#825)
  • Mail: Toast store crashed on insecure origins, breaking every post-action acknowledgement
  • Mobile: Reach the tag and move submenus in the more-actions menu (#779)
  • Mobile: iOS Safari no longer zooms the viewport on every input focus (#838)
  • Calendar: Click and double-click create events at the clicked slot instead of near the current time
  • Calendar: Save and Cancel are available when an event is created, and the toolbar no longer overflows in edit mode
  • Calendar: Edit a single recurring occurrence via a one-shot override patch
  • Calendar: Hide tasks-only calendars from the event calendar
  • Calendar: Exclude subscription and read-only calendars from event creation (#762)
  • Calendar: Rights-first event editability, including alias organizers
  • Calendar: Pin supported-calendar-component-set on created calendars (#760)
  • Calendar: Gate first-touch calendar and contacts requests to stop duplicate default calendars (#907)
  • Calendar/Contacts: Namespace all accounts consistently on switch, so multi-account address-book aggregation and calendar selection survive an account switch
  • Contacts: Import vCard dates as RFC 9553 PartialDate and map common X- extensions (#224)
  • Files: Decode percent-encoded FileNode names from WebDAV-created nodes (#869)
  • Files: Reset the account-scoped Files drive on every account switch
  • Accounts: Refresh the account display name from the Stalwart principal on login, restore, and switch (#900)
  • Auth: Reuse the cached access token on session restore (#552)
  • Auth: Refresh TOTP-minted tokens with the default client id when no OAuth client is configured (#873)
  • Auth: Store the session cookie for relative JMAP server URLs
  • Security: Close IPv6 transition-address and redirect bypasses in the endpoint guard
  • Security: Add embedded custom app origins to CSP frame-src (#787)
  • Security: Per-account isolation for encryption at rest
  • JMAP: Cap live SSE streams per tab and keep exactly one stream per client, so many logins can't starve JMAP requests (#702)
  • JMAP: Check the specific capability a request declares (principals:owner), not a broader one
  • JMAP: Resolve relative session URLs without corrupting URI templates
  • Settings: Merge per-account maps on server load, fixing the compose identity switch
  • Settings: Leaving the Pro interface returns to the surface in use and keeps the settings scroll position
  • UI: Position portalled popovers before first paint to stop the layout flash on open
  • Push: Recreate the push subscription on re-register (#841)
  • i18n: Key parity across all 24 locales, Catalan and Mongolian registered in the client provider, and scoped translation hooks instead of relative namespace paths
  • Docs: Lengthen the example SESSION_SECRET so it meets the minimum length

  •  

Icons! Lots of them! – These Weeks in Firefox: Issue 206

Highlights

  • Starting in Firefox 154, we’ve added a new capability for changing the default browser icon for Windows (Windows-only, for now, and not MSIX / Store installs) in about:settings#appearance!

Menu under Appearance settings containing a list of icons to choose from to customize the Firefox browser icon.

Settings panel checkbox to enable stylesheet handling in the debugger.

  • The Picture-in-Picture WebAPI is now available, starting with release version Firefox 153!
    • This does not replace the built-in Picture-in-Picture mechanism, and is in fact powered by it.

Friends of the Firefox team

Resolved bugs (excluding employees)

Volunteers that fixed more than one bug

  • japandi

New contributors (🌟 = first patch)

Project Updates

Add-ons / Web Extensions

Addon Manager & about:addons
  • As part of Project Nova work:
    • Added moz-promo cards to the about:addons extensions list recommendations footer and empty state, and updated the openAmoInTab helper to support a custom UTM content value – Bug 2043615 / Bug 2050880
    • Introduced the building blocks for the Nova Themes Picker in about:addons: a shared Firefox Themes list source of truth, a light/dark/device theme-mode switcher, a reusable theme-preview webcomponent, and Nova-styled theme previews – Bug 2051554 / Bug 2051559 / Bug 2051564 / Bug 2051573
    • Updated the Extensions panel empty state illustration and toolbar item icon for Project Nova – Bug 2030715
      • Thanks to Michael Hynson for driving this.
  • Removed the legacy AddonManager Glean metrics used for mirroring legacy telemetry events, along with the corresponding legacy telemetry test checks – Bug 1923949 / Bug 1981822
    • Thanks to Chris H-C for collaborating with us on this.
  • Fixed themes installed through the distribution mechanism not fetching their AMO metadata, which was resulting in distribution installed themes left without a preview image in about:addons – Bug 1917279
    • Thanks to Mike Kaply for the fix to the distribution themes metadata handling.
  • Fixed amContentHandler to verify that a system triggeringPrincipal genuinely originated from the parent process, a regression introduced in Firefox 153 and fixed in Firefox 154 (with a beta 153 uplift requested) – Bug 2048964
WebExtensions Framework
  • Fixed a startup performance regression by avoiding an NSS-initializing crypto.getRandomValues() call during extension startup, a regression introduced in Firefox 153 and fixed in Firefox 154 (with a beta 153 uplift requested) – Bug 2050882
  • Enabled tier 3 TypeScript typecheck linting for the extensions framework code – Bug 2050124
  • Implemented the WebExtensions manifest sandbox key, letting extensions keep using string-based code execution in unprivileged sandboxed extension documents – Bug 1685123
    • Thanks to Robin for the implementation of the manifest sandbox support.
WebExtension APIs
  • Enabled storage.local database auto-reset on detected corrupted IndexedDB storage on all channels, starting in Firefox 154 – Bug 1992973
  • Simplified registerTraceableChannel to make it synchronous again, removing the delay before blocking webRequest listeners can register a traceable channel – Bug 2044518
  • Restored the contextualIdentities iconUrl container icons to their intrinsic 32×32 size, fixing a regression introduced earlier in the Firefox 154 cycle – Bug 2048599
    • Thanks to Andrea Marchesini for the fix to the contextualIdentities container icons.
  • Fixed the MV2 userScripts API failing with an Xrays TypedArray access error due to a missing isWebExtensionContentScript flag – Bug 2054083
    • Thanks to erosman for the fix to the MV2 userScripts API.

DevTools

The visually updated about:debugging Performance dialog

  • Nicolas Chevobbe about:debugging is now using moz-page-nav for its left sidebar (#2048544), thanks to Mark making it possible to disable collapsing that occurs on narrow screen (#2050907)
    • (not all items were migrated to moz-page-nav-button though, see #2050746 for remaining work)
  • Alexandre Poirot made it possible to control the request and response body size limit from the Settings panel (#2040892)

A control in the Firefox DevTools Settings panel to adjust the request and response body size limit.

A notification displayed above the DevTools Inspector panel promoting Local Mode.

WebDriver

Credential Management

Migration Improvements

New Tab Page

  • That’s a wrap for the World Cup! We’re powering down the Sports widget today.
    • Some folks might see a survey about the Sports widget, to get feedback from the wild on whether or not it provided any user value (Telemetry points to “yes”, but it’s good to get qual data too)
    • We’re replacing it with some new widgets. If you’re in an English-speaking region, you will probably see it replaced with a Daily Crossword widget. Otherwise, it’ll be replaced with a Picture of the Day widget.
  • Sections have rolled out to 100% in France! We’re now doing 10% Sections experiments in Spain, Italy, Austria, Switzerland and Belgium.
  • Shout out to volunteer Sameeksha who added an accessible name to the Task list widget ••• button, adding an aria-label/accessible-name so NVDA/VoiceOver announce the control and keyboard navigation/activation works correctly on New Tab.
  • Joel added WebNotifications to the newtab state, allowing New Tab widgets to observe and reflect WebNotification events (affects the notification-driven widget lifecycle and UI state updates).
  • Reem Hamoui adjusted the New-Tab Widgets 3-dot menu layout to vertically center menu entries inside the hover-granted colorful stripe, removing visual misalignment and small hit-area offsets on touch and pointer inputs.
  • Dre implemented the show less/show more transition animation for New Tab expand/collapse, smoothing layout shifts with a CSS transition to reduce perceived jank during widget list changes.
  • Scott Downe fixed New Tab Page drag-and-drop so widgets no longer jump or keep moving during drags (2049472).
  • Reem Hamoui rendered the Daily Crossword in a sandboxed iframe to isolate its scripts/CSP on the New Tab Page (2049489).
  • Reem Hamoui added the Crossword option to about:preferences and wired the New Tab Page crossword widget into prefs (2050340), so users can enable or disable the crossword via the standard Preferences UI rather than about:config.
  • Dre set up the Picture of the Day boilerplate, including prefs and basic New Tab UI components (2050969), which exposes a configurable PoD surface for users to opt into and customize.
  • Dre added a dismiss control and persisted dismissal state to the daily photo UI (2050972), allowing users to remove the current picture from their New Tab and avoid immediate reappearance.
  • Dre added a “set as wallpaper” action and hooked it into New Tab wallpaper storage/prefs (2050973), enabling users to promote a PoD image to their custom New Tab wallpaper persistently.
  • Dre connected the Picture of the day widget to the Merino endpoint to set the background of the widget to the current picture (2050976). He also added telemetry for the Picture of the day widget on the New Tab Page to capture impressions and clicks for usage analysis (2050977).
  • Nina Pypchenko [:nina-py] added a small size variant for the Focus Timer widget in Nova so the timer can render compactly in narrow/new tab layouts and reduce vertical space usage (2051179).
  • Maxx Crawford created a DevTools ‘controls’ area on the New Tab Page to enable and configure the widget, exposing toggles and settings that let developers and experimenters flip the widget without changing prefs, which reduces friction when reproducing NTP widget behaviors during debugging and testing.
  • Irene Ni switched the New Tab ‘inferred personalization’ checkbox to the platform moz-checkbox control, restoring native checkbox semantics (role/keyboard focus/visual state) so users toggling inferred personalization see consistent a11y behavior and platform rendering across Windows/macOS/Linux.
  • Scott Downe fixed an intermittent visual reload/flicker of sponsored tiles and the Add Shortcut button when pinning/unpinning shortcuts, preventing momentary tile DOM reflows and layout thrash that caused perceived data loss or longer perceived latency during shortcut edits.
  • Scott Downe ensured custom image URLs persist on manually added Top Site tiles after edit, so users’ uploaded or external thumbnails no longer revert to the site’s homepage preview when saving edits and their custom thumbnails are correctly cached and displayed.
  • Dre introduced two variants of the World Cup widget survey message, changing the copy delivered in the widget to support an A/B/message-variant experiment and altering what users see when the World Cup widget surfaces survey prompts on their New Tab Page.
  • Nina Pypchenko [:nina-py] introduced a default state for Medium and Large Stocks widget sizes on the New Tab Page to surface placeholder content and avoid blank tiles when the Stocks feed is empty or slow to load.
  • Nina Pypchenko [:nina-py] added an error state to the Stocks widget on the New Tab Page to show an explicit failure UI when quote fetches or network requests fail, reducing user confusion.
  • Alexandre Hanot migrated AdsFeed to fetch New Tab ads through the MozAdsClient, changing the ad retrieval path (AdsFeed -> MozAdsClient) which affects ads loading behavior and telemetry for users who see New Tab Page ads.
  • Irene Ni fixed the New Tab add-pin flow that was creating extra rows when grouped pins was off by changing the insertion logic to append into the existing grid, which eliminates unexpected row creation and layout shifts for users managing many pins (2053251).
  • Scott Downe updated New Tab section rendering to hide cards that don’t fill their row by adjusting layout logic/CSS, removing orphaned placeholders and reducing blank space on narrow viewports or low-item sections for a cleaner grid appearance (2053264).
  • Reem Hamoui added a context menu to the Crossword widget using a postMessage integration between the iframe and parent page, enabling right-click actions (copy/hint/theme) and making the embedded crossword more interactive and accessible to users who rely on context menus (2053311).
  • Reem Hamoui added a visible “New” badge plus interaction handlers and state tracking to the Crossword widget on the New Tab Page to improve discoverability and make tapping/clicking behave reliably when launching puzzles (2053667).
  • Irene Ni removed unused Add Shortcut OMC artifacts from the New Tab Page (2053843); this is a cleanup of obsolete assets/templates and has no direct runtime user impact.
  • Maxx Crawford added author and license attribution to the Picture of the Day widget (2053933); this surfaces photographer credit and license metadata on the New Tab Page for users who want provenance information.
  • Maxx Crawford applied UX refinements to the Picture of the Day widget (2054109); users will see improved layout, spacing, and touch targets in the POTD area for clearer interactions.
  • Maxx Crawford added a pref and trainhopConfig gate to toggle the POTD “Set as wallpaper” feature (2054111); rollout and availability of the wallpaper action are now controllable via pref and remote trainhopConfig.
  • Maxx Crawford added a dedicated trainhopConfig.widgetPictureOfTheDay payload for POTD feature config (bug 2054112) so the New Tab Page train-hop widget can be controlled server-side — this delivers image URLs, attribution and display params remotely which lets us enable/disable POTD per cohort without ship-side changes and reduces rollout latency for users who see the Picture‑of‑the‑Day widget.
  • Irene Ni updated the Shortcuts Add/Edit dialog for Nova (bug 2054175) to improve the add/edit UX on the New Tab Shortcuts surface — the patch adjusts dialog layout and controls, tightens validation and accessibility labels, and reduces accidental duplicate/invalid shortcut creation so users editing shortcuts have a more reliable, faster flow.
  • Maxx Crawford fixed the Daily crossword widget content overflowing and clipping past the bottom container boundary by adjusting the crossword widget’s layout/CSS (container height calculations and overflow/overflow-anchor rules) on the New Tab Page, restoring full visibility of clues and controls across responsive breakpoints.
  • Maxx Crawford fixed Related articles not opening on click by repairing the related-articles component’s click handling and event delegation (anchor href/target behavior and JS listener) on the New Tab Page so article tiles now reliably open on click for users.
  • Maxx Crawford added a “New” badge and interactions to the Picture of the Day widget, implementing an isNew flag, local state/localStorage handling, ARIA label updates and click behavior so users can immediately see and act on newly added images.
  • Maxx Crawford updated the initial order of the Picture of the day widget by changing the PoD component’s initial ordering/priority algorithm so first-run and default NTP surfaces surface curated/high-priority images first.
  • Maxx Crawford migrated Crossword widget strings from Fluent back to inline markup to fix localization/formatting regressions in the crossword UI and ensure consistent rendering of labels and controls across locales.
  • Irene Ni migrated the New Tab Widgets expand button to moz-button which standardizes the expand/collapse control on the New Tab Page widgets area, fixing inconsistent styling and keyboard/click handling so users now get consistent visuals and improved accessibility across platforms.
  • Reem Hamoui added a dedicated trainhopConfig.widgetCrossword payload for Crossword feature config which isolates crossword rollout flags and content settings from other trainhop payloads, allowing targeted remote-config changes and safer A/B testing of the crossword widget without impacting unrelated New Tab features.
  • Maxx Crawford fixed the Daily crossword widget being blank after closing and reopening the browser by ensuring widget state is correctly initialized/persisted on startup (New Tab Page widget lifecycle), so users now reliably see the daily puzzle after a restart instead of an empty frame.
  • Reem Hamoui fixed Daily crossword completed puzzle and show clues are displayed in medium sized widget, restoring completed-puzzle rendering and clue visibility in the New Tab Page medium widget (widget template/CSS).
  • Maxx Crawford updated Discovery Stream Admin buttons to use moz-button components, replacing custom controls with moz-button to standardize admin UI styling and focus behavior.
  • Maxx Crawford added per-widget feature toggles and pref reset buttons to Discovery Stream Admin, enabling admins to toggle individual widgets and reset prefs without code deploys — changes here can alter what users see when toggled.
  • Maxx Crawford migrated Discovery Stream Admin unit tests to jest, moving tests to Jest for faster developer feedback and more consistent test tooling.
  • Maxx Crawford enforced Fail jest tests that emit console.error messages, making tests fail on console.error to catch regressions earlier and improve content quality before release.
  • Kyle Jones populated MozAdsRequestOptions flags from adsBackendConfig in AdsFeed on the New Tab Page, changing ad request parameters that may alter which ads or personalization users see.
  • Mike Conley removed the version 145 train-hop shim for the PrivacyFeed getTodayStats guard, simplifying guard logic in the New Tab Page with no direct user-visible change.

Search and Urlbar

Search
  • Mandy fixed the “New” label incorrectly appearing for user-installed third party search engines that override application-provided engines (2053710).
  • Standard8 fixed search engine telemetry notifications and private browsing search engine defaults (2053129, 1792669).
Suggest
  • Adw added header_text support for AMP (AdMarketPlace) suggestions (2053626).
Nova
Address Bar
Places & Bookmarks

Storybook/Reusable Components/Acorn Design System

  • Nova stuff
  • Theme Picker for HNT, OMC and Profiles
  • [mconley] There’s a new vertical variant for visual picker. Thanks for the reviews, hjones!
  •  

v12.3.1

✨ New Features & Improvements

  • @directus/api
    • Added countFilterListeners, countActionListeners, and countInitListeners methods to the emitter, exposing the number of registered handlers for each event (#28117 by @ComfortablyCoding)

🐛 Bug Fixes & Optimizations

  • @directus/app
    • Fixed MCP OAuth clients settings pages concatenating breadcrumbs into the page title (#28115 by @MHJahanbakhsh)
  • @directus/api
    • Fixed the WebSocket heartbeat leaking a websocket.message listener on each ping when a client failed to respond in time (#28117 by @ComfortablyCoding)
    • Fixed GraphQL query fragments returning null fields (#28128 by @ComfortablyCoding)
    • Fixed public registration verification using the provided email instead of the stored one (#28144 by @br41nslug)
    • Removed user_created and date_created for update from recommended permissions for directus_shares (#28145 by @br41nslug)
    • Updated storage driver dependencies (#28119 by @ComfortablyCoding)
  • @directus/cli
    • Stripped project_id when pulling settings, so a sync no longer copies one instance's identity onto another (#28132 by @lazerg)
  • @directus/sdk
    • Fixed unsubscribe() not removing subscriptions, causing them to persist across reconnects and accumulate for the lifetime of the client (#28117 by @ComfortablyCoding)
  • @directus/system-data
    • Removed user_created and date_created for update from recommended permissions for directus_shares (#28145 by @br41nslug)
  • @directus/storage-driver-s3
  • @directus/storage-driver-gcs
  • @directus/storage-driver-azure
  • @directus/storage-driver-supabase

📦 Published Versions

  • @directus/app@17.1.1
  • @directus/api@39.1.0
  • @directus/cli@12.2.1
  • @directus/composables@11.6.2
  • create-directus-extension@12.1.4
  • @directus/env@6.2.2
  • @directus/extensions@4.0.4
  • @directus/extensions-sdk@18.0.4
  • @directus/memory@4.0.4
  • @directus/pressure@4.0.4
  • @directus/storage-driver-azure@13.0.4
  • @directus/storage-driver-cloudinary@14.0.1
  • @directus/storage-driver-gcs@13.0.4
  • @directus/storage-driver-s3@14.0.1
  • @directus/storage-driver-supabase@5.0.1
  • @directus/system-data@4.6.1
  • @directus/themes@2.0.4
  • @directus/utils@13.5.4
  • @directus/validation@3.0.4
  • @directus/sdk@25.0.1

  •  

Minecraft 26.3-snapshot-10 (snapshot) Released

26.3 Snapshot 10 (known as 26.3-snapshot-10 in the launcher) is the tenth snapshot for Java Edition 26.3, released on August 25, 2026, which changes the panorama for the next game drop, renames explorer maps, and fixes bugs. Full changelog: https://minecraft.wiki/Java_Edition_26.3-snapshot-10
  •  

Firefox 154.0.1

Fixed

  • Fixed slower access to saved passwords and unexpected Primary Password prompts caused by recent changes to password storage. (Bug 2064411, Bug 2065593, Bug 2063993)

  • Fixed an issue where addresses were failing to autofill on some sites. (Bug 2065145, Bug 2063599)

  • Fixed Firefox adding a new Start Menu shortcut on Windows every time it started. (Bug 2064652)

  • Fixed an issue where connections to local network devices were failing without a permission prompt on some sites loaded over HTTP. (Bug 2059274)

  • Fixed a crash that could occur when opening intranet sites that are configured to link to files on a local network share. (Bug 2064648)

  • Fixed an issue on Windows where tab titles were cut off at the start when the system font was MS UI Gothic. (Bug 2056856)

Unresolved

  • For users with vertical tabs enabled, the sidebar may not persist across Firefox restarts. Vertical tabs can be re-enabled after the restart by clicking the sidebar toolbar button. A fix is currently in development. (Bug 2065431)

  • When toolbars are hidden in fullscreen mode (the default on Windows and Linux), the vertical tabs sidebar does not appear when moving the cursor to the left edge of the screen. As a workaround, move the cursor to the top of the screen to reveal both toolbars and sidebar together. Alternatively, you can also right-click the toolbar and uncheck the Hide toolbars option. We are currently working on a fix. (Bug 2064638)

  •  

MariaDB Server 12.3, 11.8, 11.4 and 10.11 – Q3 2026 Maintenance Releases, and Goodbye 10.6

MariaDB Server maintenance releases are here!
On August 24, we released updates for our four currently maintained Long Term Support series:
As usual, these maintenance releases include bug fixes, stability improvements, and ongoing work across MariaDB Server. …

Continue reading \"MariaDB Server 12.3, 11.8, 11.4 and 10.11 – Q3 2026 Maintenance Releases, and Goodbye 10.6\"

MariaDB Server 12.3, 11.8, 11.4 and 10.11 – Q3 2026 Maintenance Releases, and Goodbye 10.6 appeared first on MariaDB.org

  •  

9.8.6

  • Fully new mobile web version
  • Fixed SQL, XML and CSV injection vulnerabilities
  • Fixed user not being logged out from other sessions after changing account password
  • Restored AllowUsedDevices functionality
  • Fixed missing linebreaks in forwarded message headers
  • Fixed losing contact's friendly name when reopening a message draft
  • Improved performance of Mail folder loading
  • Fixed folder creation with a long name in Files
  • Fixed system user group returning an empty Email list
  • Fixed UpdateGroup not updating group contacts correctly
  • Fixed public calendar shown as empty
  • Fixed visual issues in the list of own PGP keys
  • Various fixes and improvements
  •  

Counter-Strike 2 Update

[p]\[ MAP SCRIPTING ][/p]
  • [p]Added custom_hud_layout entity:[/p]
    • [p]custom_hud_layouts are the entry point for scripted maps to provide custom UI.[/p][/*]
    • [p]Panel, Label, Image, and Button panel types are supported.[/p][/*]
    • [p]Styling with css is supported.[/p][/*]
    • [p]Events and client side scripting are not supported.[/p][/*]
    • [p]Maintains state during tools mode reloads.[/p][/*]
    [/*]
  • [p]Added cs_player_camera entity:[/p]
    • [p]Gives control of a player's view without moving their pawn.[/p][/*]
    • [p]Can be configured to let the player look around from the scripted position.[/p][/*][/*]
    • [p]Added Instance.Delay[/p][/*]
    • [p]Added Instance.OnBombPlantStart[/p][/*]
    • [p]Added Instance.OnBombPlantAbort[/p][/*]
    • [p]Added Instance.OnBombDefuseStart[/p][/*]
    • [p]Added Instance.OnBombDefuseAbort[/p][/*]
    • [p]Added Instance.OnCustomHudClicked[/p][/*]
    • [p]Added Instance.IsDedicatedServer[/p][/*]
    • [p]Added Entity.Move[/p][/*]
    • [p]Added Entity.GetMoveType[/p][/*]
    • [p]Added Entity.SetMoveType[/p][/*]
    • [p]Added CSPlayerPawn.GetC4[/p][/*]
    • [p]Added CSPlayerPawn.GetDefuseTarget[/p][/*]
    • [p]Added CSPlayerPawn.IsBuyMenuOpen[/p][/*]
    • [p]Added CSPlayerPawn.GetCamera[/p][/*]
    • [p]Added C4.GetPlantStartTime[/p][/*]
    • [p]Added C4.GetPlantFinishTime[/p][/*]
    • [p]Added C4.AbortPlant[/p][/*]
    • [p]Added CustomHudLayout.SetHasClass[/p][/*]
    • [p]Added CustomHudLayout.SetHasClassForPlayer[/p][/*]
    • [p]Added CustomHudLayout.SetDialogVariableString[/p][/*]
    • [p]Added CustomHudLayout.SetDialogVariableStringForPlayer[/p][/*]
    • [p]Added CustomHudLayout.SetInputCaptureEnabled[/p][/*]
    • [p]Added CustomHudLayout.IsInputCaptureEnabled[/p][/*]
    • [p]Added CSPlayerCamera.IsEnabled[/p][/*]
    • [p]Added CSPlayerCamera.SetEnabled[/p][/*]
    • [p]Added CSPlayerCamera.SetIsControllingAngles[/p][/*]
    • [p]Added enum CSMoveType[/p][/*]
    • [p]Corrected types for some events where parameters were maybe undefined.[/p][/*]
    • [p]Errors encountered during initial script run are now logged to the console.[/p][/*]
    • [p]Unhandled promise rejections are now logged to the console.[/p][/*]
    • [p]Added the column number to errors caught during the CompileModule step of script loading.[/p][/*]
    • [p]Deprecated planter from Instance.OnBombPlant event[/p][/*]
    • [p]Deprecated defuser from Instance.OnBombDefuse event[/p][/*]
      •  

      uNmINeD 0.20.3-dev

      New uNmINeD development snapshot is available for download!

      Changes:

      • Bedrock LevelDB log file reader optimizations (speedup for worlds with large log files)
      • Isometric mode optimizations (huge speedup, less memory usage)
      • Isometric mode now uses the block filter settings
      • Added support for Java Edition default blockstates (from 26.3-snapshot-7)
      • Upgraded to .NET 11 (preview.7)

      Default blockstates

      Minecraft Java Edition from version 26.3-snapshot-7 does not store blockstate properties in the world save files when referencing a default blockstate. This caused these blockstates to render incorrectly.

      uNmINeD now uses a configuration file config/vanilla.defaultblockstates.java.txt to resolve default vanilla blockstate properties. If it encounters a blockstate reference without properties, it will use the default properties from the configuration file.

      The configuration file only contains default blockstate information for vanilla blocks. A mod will be available later that will allow you to generate a blockstate configuration file for modded worlds.

      •  
      ❌