The Chrome team is delighted to announce the promotion of Chrome 153 to the stable channel for Windows, Mac and Linux. This will roll out over the coming days/weeks.
Chrome 153.0.8010.36 (Linux) 153.0.8010.36/.37 Windows/Mac contains a number of fixes and improvements -- a list of changes is available in the log. Watch out for upcomingChrome and Chromium blog posts about new features and big efforts delivered in 153.
Security Fixes and Rewards
Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.
This update includes 230 security fixes. Please see the Chrome Security Page for more information.
[$2,500][544163112] Critical CVE-2026-87464: Use after free in WebGL. Reported by Lexi Groves (49016) on 2026-08-08
[N/A][546252753] Critical CVE-2026-87488: Use after free in WebGL. Reported by Google on 2026-08-14
[N/A][548127218] Critical CVE-2026-87438: Out of bounds write in WebGL. Reported by Google on 2026-08-18
[N/A][548130125] Critical CVE-2026-87527: Buffer overflow in WebGL. Reported by Google on 2026-08-18
[TBD][553770012] Critical CVE-2026-87628: Use after free in Cast. Reported by Hafiizh on 2026-08-28
[$2,500][541715128] High CVE-2026-87512: Use after free in ANGLE. Reported by weihengqiuu on 2026-08-02
[$500][540817065] High CVE-2026-87585: Double free in PDFium. Reported by Jeongkihyun on 2026-07-30
[TBD][489489002] High CVE-2026-87444: Memory corruption in Codecs. Reported by Casper Woudenberg on 2026-03-03
[N/A][503464711] High CVE-2026-87447: Incorrect authorization in Network. Reported by Google on 2026-04-16
[N/A][513458719] High CVE-2026-87440: Out of bounds read in Media. Reported by Google on 2026-05-15
[N/A][516996291] High CVE-2026-87633: Use after free in Views. Reported by Google on 2026-05-27
[N/A][517336350] High CVE-2026-87525: Out of bounds read in Chromoting. Reported by Google on 2026-05-28
[N/A][517371367] High CVE-2026-87578: Use after free in Receiver. Reported by Google on 2026-05-28
[N/A][517581661] High CVE-2026-87517: Race condition in Mobile. Reported by Google on 2026-05-28
[N/A][522546457] High CVE-2026-87524: Use after free in Core. Reported by Google on 2026-06-11
[N/A][523277481] High CVE-2026-87569: Missing authorization in Views. Reported by Google on 2026-06-12
[N/A][524423633] High CVE-2026-87554: Race condition in Chromoting. Reported by Google on 2026-06-16
[N/A][524453236] High CVE-2026-87467: Race condition in Updater. Reported by Google on 2026-06-16
[TBD][529123409] High CVE-2026-87492: Incorrect authorization in DevTools. Reported by Avadhut Mahamuni on 2026-06-29
[N/A][529878021] High CVE-2026-87520: Use after free in Dawn. Reported by Google on 2026-06-30
[N/A][532916987] High CVE-2026-87514: Use after free in Views. Reported by Google on 2026-07-09
[N/A][534912743] High CVE-2026-87650: Out of bounds read in WebGL. Reported by Google on 2026-07-14
[N/A][536434693] High CVE-2026-87596: Out of bounds read in ANGLE. Reported by Google on 2026-07-19
[N/A][536444790] High CVE-2026-87654: Buffer overflow in ANGLE. Reported by Google on 2026-07-19
[N/A][536648007] High CVE-2026-87604: Out of bounds read in ANGLE. Reported by Google on 2026-07-19
[N/A][536664909] High CVE-2026-87621: Out of bounds write in ANGLE. Reported by Google on 2026-07-20
[N/A][536673946] High CVE-2026-87647: Uninitialized resource in GPU. Reported by Google on 2026-07-20
[TBD][539754136] High CVE-2026-87646: Use after free in Web Authentication. Reported by h3ee on 2026-07-28
[N/A][540019091] High CVE-2026-87500: Improper validation of array index in ANGLE. Reported by Google on 2026-07-28
[N/A][540021969] High CVE-2026-87572: Injection in DevTools. Reported by Google on 2026-07-28
[N/A][540058837] High CVE-2026-87460: Use after free in Platform. Reported by Google on 2026-07-28
[N/A][542756749] High CVE-2026-87542: Use after free in Input. Reported by Google BigSleep@Grape on 2026-08-05
[TBD][544415098] High CVE-2026-87639: Use after free in WebPackaging. Reported by OpenAI Codex Security (amyb) on 2026-08-09
[TBD][547426657] High CVE-2026-87552: Missing authorization in TrustedWebActivities. Reported by juddrouillon0 on 2026-08-16
[TBD][550141694] High CVE-2026-87651: Incorrect authorization in Paint. Reported by OGINOME Tomohito on 2026-08-21
[TBD][550360762] High CVE-2026-87587: Use after free in V8. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern) on 2026-08-21
[TBD][552342545] High CVE-2026-87564: Type confusion in V8. Reported by Tech Division (@taiphung) - Mobifone Digital Payment on 2026-08-25
[N/A][552413517] High CVE-2026-87498: Missing authorization in WebUI. Reported by Google on 2026-08-25
[N/A][553118043] High CVE-2026-87499: Incorrect authorization in Network. Reported by Google on 2026-08-26
[N/A][553122131] High CVE-2026-87607: Use after free in Device. Reported by Google on 2026-08-26
[N/A][553128689] High CVE-2026-87558: Use after free in Payments. Reported by Google on 2026-08-26
[N/A][553129531] High CVE-2026-87581: Use after free in Payments. Reported by Google on 2026-08-26
[N/A][553928324] High CVE-2026-87480: Use after free in Printing. Reported by Google on 2026-08-28
[TBD][554236352] High CVE-2026-87612: Type confusion in V8. Reported by ywatanabee on 2026-08-29
[TBD][554421904] High CVE-2026-87536: Use after free in V8. Reported by StinkyTuna56 on 2026-08-29
[N/A][554558968] High CVE-2026-87474: Use after free in Payments. Reported by Google on 2026-08-29
[$5,000][499206649] Medium CVE-2026-87504: Use after free in Core. Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-04-03
[$3,000][498482618] Medium CVE-2026-87640: Out of bounds read in WebView. Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-04-01
[$2,500][543557673] Medium CVE-2026-87491: Out of bounds write in V8. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern) on 2026-08-06
[$2,000][40060525] Medium CVE-2026-87478: Observable discrepancy in Autofill. Reported by Maurice Dauer on 2022-08-07
[$2,000][483435192] Medium CVE-2026-87446: Incomplete cleanup in Extensions. Reported by Hafiizh on 2026-02-11
[$1,000][542146471] Medium CVE-2026-87657: Use after free in V8. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern) on 2026-08-03
[N/A][493322521] Medium CVE-2026-87434: Missing authorization in CORS. Reported by Google on 2026-03-17
[N/A][495429423] Medium CVE-2026-87487: Missing authorization in FileSystem. Reported by Google on 2026-03-23
[N/A][495444970] Medium CVE-2026-87453: Confused deputy in BackgroundFetch. Reported by Google on 2026-03-23
[N/A][495515356] Medium CVE-2026-87588: Use after free in Chromecast. Reported by Google on 2026-03-23
[N/A][495541478] Medium CVE-2026-87636: Type confusion in XML. Reported by Google on 2026-03-23
[N/A][495876543] Medium CVE-2026-87611: Missing authorization in FileSystem. Reported by Google on 2026-03-24
[N/A][495933780] Medium CVE-2026-87606: Missing authorization in SiteIsolation. Reported by Google on 2026-03-25
[N/A][496231550] Medium CVE-2026-87456: Uninitialized resource in Media. Reported by Google on 2026-03-25
[N/A][496595299] Medium CVE-2026-87553: Improper input validation in SiteIsolation. Reported by Google on 2026-03-26
[N/A][496615345] Medium CVE-2026-87658: Information leak in Extensions. Reported by Google on 2026-03-26
[N/A][496616790] Medium CVE-2026-87465: Incorrect authorization in Downloads. Reported by Google on 2026-03-26
[N/A][497093426] Medium CVE-2026-87515: Incorrect authorization in FileAPI. Reported by Google on 2026-03-28
[N/A][497111188] Medium CVE-2026-87547: Incorrect reference resolution in FileSystem. Reported by Google on 2026-03-28
[N/A][497443419] Medium CVE-2026-87442: Confused deputy in Prerender. Reported by Google on 2026-03-29
[N/A][497551905] Medium CVE-2026-87506: Privilege elevation in WebUI. Reported by Google on 2026-03-29
[N/A][497574154] Medium CVE-2026-87433: Race condition in FileAPI. Reported by Google on 2026-03-30
[N/A][497635917] Medium CVE-2026-87557: Missing authorization in LocalNetworkAccess. Reported by Google on 2026-03-30
[N/A][497837188] Medium CVE-2026-87457: Race condition in Updater. Reported by Google on 2026-03-30
[N/A][497986036] Medium CVE-2026-87503: Inappropriate implementation in Downloads. Reported by Google on 2026-03-31
[N/A][498730641] Medium CVE-2026-87481: Incorrect authorization in WebView. Reported by Google on 2026-04-01
[N/A][498732709] Medium CVE-2026-87537: Missing authorization in Extensions. Reported by Google on 2026-04-01
[N/A][498869663] Medium CVE-2026-87471: Incorrect authorization in ServiceWorker. Reported by Google on 2026-04-02
[N/A][499230506] Medium CVE-2026-87485: Incorrect authorization in CORS. Reported by Google on 2026-04-03
[N/A][499425100] Medium CVE-2026-87652: Incorrect authorization in PushAPI. Reported by Google on 2026-04-04
[N/A][500094528] Medium CVE-2026-87582: Confused deputy in DataTransfer. Reported by Google on 2026-04-06
[N/A][500467033] Medium CVE-2026-87466: Incorrect authorization in Workers. Reported by Google on 2026-04-07
[N/A][501627201] Medium CVE-2026-87603: Missing authorization in FileSystem. Reported by Google on 2026-04-11
[N/A][501643868] Medium CVE-2026-87615: Race condition in Payments. Reported by Google on 2026-04-11
[N/A][501644790] Medium CVE-2026-87642: Uninitialized resource in WebGL. Reported by Google on 2026-04-11
[N/A][501700023] Medium CVE-2026-87577: Incorrect authorization in Isolated. Reported by Google on 2026-04-11
[N/A][501850947] Medium CVE-2026-87449: Cross-site request forgery in DeviceBoundSessionCredentials. Reported by Google on 2026-04-12
[N/A][501889544] Medium CVE-2026-87613: Incorrect reference resolution in Extensions. Reported by Google on 2026-04-12
[N/A][502611474] Medium CVE-2026-87645: Improper state validation in Safebrowsing. Reported by Google on 2026-04-14
[N/A][502768228] Medium CVE-2026-87443: Missing authorization in Actor. Reported by Google on 2026-04-15
[TBD][502783118] Medium CVE-2026-87630: Integer overflow in WebRTC. Reported by ngrunbaum on 2026-04-15
[N/A][502814490] Medium CVE-2026-87590: Improper input validation in Passwords. Reported by Google on 2026-04-15
[N/A][502986244] Medium CVE-2026-87580: Incorrect authorization in WebAppInstalls. Reported by Google on 2026-04-15
[N/A][503736006] Medium CVE-2026-87482: Cleartext transmission of sensitive data in HttpsUpgrades. Reported by Google on 2026-04-17
[N/A][504670493] Medium CVE-2026-87497: Uninitialized resource in Codecs. Reported by Google on 2026-04-20
[N/A][504690157] Medium CVE-2026-87579: Buffer overflow in WebRTC. Reported by Google on 2026-04-20
[N/A][506385755] Medium CVE-2026-87576: Uninitialized resource in GPU. Reported by Google on 2026-04-25
[N/A][506390077] Medium CVE-2026-87476: Incorrect authorization in Loader. Reported by Google on 2026-04-25
[N/A][507225626] Medium CVE-2026-87475: Missing authorization in Omnibox. Reported by Google on 2026-04-28
[N/A][511754574] Medium CVE-2026-87436: Incomplete cleanup in Browser. Reported by Google on 2026-05-10
[N/A][511772271] Medium CVE-2026-87479: Insufficient policy enforcement in Extensions. Reported by Google on 2026-05-10
[N/A][511773417] Medium CVE-2026-87513: Missing authorization in ControlledFrame. Reported by Google on 2026-05-10
[N/A][511820041] Medium CVE-2026-87432: Incorrect authorization in Navigation. Reported by Google on 2026-05-10
[N/A][511824746] Medium CVE-2026-87560: Missing authorization in Browser. Reported by Google on 2026-05-10
[N/A][512986143] Medium CVE-2026-87521: Information leak in WebMCP. Reported by Google on 2026-05-13
[N/A][513003268] Medium CVE-2026-87539: Observable discrepancy in Network. Reported by Google on 2026-05-14
[N/A][513048243] Medium CVE-2026-87648: Use after free in ANGLE. Reported by Google on 2026-05-14
[N/A][513134173] Medium CVE-2026-87534: Missing authorization in WebView. Reported by Google on 2026-05-14
[N/A][513135531] Medium CVE-2026-87562: Incorrect reference resolution in Accessibility. Reported by Google on 2026-05-14
[N/A][513192482] Medium CVE-2026-87556: Missing authorization in Browser. Reported by Google on 2026-05-14
[N/A][513346220] Medium CVE-2026-87508: Incorrect authorization in Loader. Reported by Google on 2026-05-14
[N/A][513416699] Medium CVE-2026-87643: Integer overflow in GPU. Reported by Google on 2026-05-15
[N/A][513438970] Medium CVE-2026-87573: Improper input validation in Network. Reported by Google on 2026-05-15
[N/A][513495219] Medium CVE-2026-87548: Improper state validation in Installer. Reported by Google on 2026-05-15
[N/A][513509804] Medium CVE-2026-87501: UI misrepresentation in Passwords. Reported by Google on 2026-05-15
[N/A][513524705] Medium CVE-2026-87452: Incorrect authorization in GPU. Reported by Google on 2026-05-15
[N/A][513608513] Medium CVE-2026-87516: Observable discrepancy in Navigation. Reported by Google on 2026-05-15
[N/A][513702096] Medium CVE-2026-87599: Improper input validation in Interstitials. Reported by Google on 2026-05-16
[N/A][514009699] Medium CVE-2026-87507: UI misrepresentation in Downloads. Reported by Google on 2026-05-17
[N/A][514011926] Medium CVE-2026-87559: UI misrepresentation in UI. Reported by Google on 2026-05-17
[N/A][514016678] Medium CVE-2026-87472: Improper input validation in FedCM. Reported by Google on 2026-05-17
[N/A][514017067] Medium CVE-2026-87486: Clickjacking in TrustedWebActivities. Reported by Google on 2026-05-17
[N/A][514023309] Medium CVE-2026-87655: Clickjacking in Downloads. Reported by Google on 2026-05-17
[N/A][514041087] Medium CVE-2026-87462: UI misrepresentation in FedCM. Reported by Google on 2026-05-17
[N/A][514055890] Medium CVE-2026-87649: UI misrepresentation in Downloads. Reported by Google on 2026-05-17
[N/A][514056835] Medium CVE-2026-87445: UI misrepresentation in Session. Reported by Google on 2026-05-17
[N/A][514069596] Medium CVE-2026-87567: UI misrepresentation in UrlFormatting. Reported by Google on 2026-05-17
[N/A][514074827] Medium CVE-2026-87496: UI misrepresentation in Browser. Reported by Google on 2026-05-17
[N/A][514556469] Medium CVE-2026-87441: Missing authorization in Downloads. Reported by Google on 2026-05-19
[N/A][516534546] Medium CVE-2026-87549: Incomplete cleanup in Downloads. Reported by Google on 2026-05-25
[N/A][517072005] Medium CVE-2026-87458: UI misrepresentation in Geometry. Reported by Google on 2026-05-27
[N/A][517092658] Medium CVE-2026-87574: Information leak in ServiceWorker. Reported by Google on 2026-05-27
[N/A][517122234] Medium CVE-2026-87495: Information leak in Scroll. Reported by Google on 2026-05-27
[N/A][517156678] Medium CVE-2026-87541: Information leak in Navigation. Reported by Google on 2026-05-27
[N/A][517178299] Medium CVE-2026-87451: Information leak in Downloads. Reported by Google on 2026-05-27
[N/A][517215407] Medium CVE-2026-87570: Incorrect authorization in SiteIsolation. Reported by Google on 2026-05-27
[N/A][517337579] Medium CVE-2026-87555: Uninitialized resource in GPU. Reported by Google on 2026-05-28
[N/A][517339356] Medium CVE-2026-87600: Improper input validation in Safebrowsing. Reported by Google on 2026-05-28
[N/A][517369256] Medium CVE-2026-87532: Improper state validation in Safebrowsing. Reported by Google on 2026-05-28
[N/A][517415433] Medium CVE-2026-87439: Information leak in ServiceWorker. Reported by Google on 2026-05-28
[N/A][517432155] Medium CVE-2026-87450: Incorrect authorization in Permissions. Reported by Google on 2026-05-28
[N/A][517597701] Medium CVE-2026-87505: Incorrect authorization in FileSystem. Reported by Google on 2026-05-28
[N/A][517602176] Medium CVE-2026-87622: Missing authorization in FedCM. Reported by Google on 2026-05-28
[N/A][517721914] Medium CVE-2026-87540: Incorrect authorization in Isolated. Reported by Google on 2026-05-29
[N/A][517732336] Medium CVE-2026-87594: Incorrect authorization in DataTransfer. Reported by Google on 2026-05-29
[N/A][517917560] Medium CVE-2026-87518: Observable discrepancy in Safebrowsing. Reported by Google on 2026-05-29
[N/A][518002426] Medium CVE-2026-87589: Incorrect authorization in SiteIsolation. Reported by Google on 2026-05-29
[N/A][518039263] Medium CVE-2026-87484: UI misrepresentation in Geometry. Reported by Google on 2026-05-29
[N/A][518081914] Medium CVE-2026-87530: Uncontrolled search path element in CredentialProvider. Reported by Google on 2026-05-30
[N/A][518082852] Medium CVE-2026-87550: Improper encoding or escaping of output in CSS. Reported by Google on 2026-05-30
[N/A][520161438] Medium CVE-2026-87494: Use after free in Browser. Reported by Google on 2026-06-05
[N/A][520201931] Medium CVE-2026-87483: Incorrect authorization in Browser. Reported by Google on 2026-06-05
[N/A][520389619] Medium CVE-2026-87454: Information leak in Enterprise. Reported by Google on 2026-06-05
[N/A][520469117] Medium CVE-2026-87616: Improper initialization in Views. Reported by Google on 2026-06-05
[N/A][520572550] Medium CVE-2026-87535: Information loss or omission in Safebrowsing. Reported by Google on 2026-06-06
[N/A][521616899] Medium CVE-2026-87644: Incorrect authorization in Views. Reported by Google on 2026-06-09
[N/A][521620916] Medium CVE-2026-87533: Use after free in DevTools. Reported by Google on 2026-06-09
[N/A][522304737] Medium CVE-2026-87635: UI misrepresentation in Payments. Reported by Google on 2026-06-10
[N/A][523091391] Medium CVE-2026-87641: Race condition in Browser. Reported by Google on 2026-06-12
[N/A][523313374] Medium CVE-2026-87431: Missing authorization in Extensions. Reported by Microsoft Edge on 2026-06-12
[N/A][523741272] Medium CVE-2026-87493: Missing authorization in FileSystem. Reported by Google on 2026-06-14
[N/A][532921336] Medium CVE-2026-87625: Use after free in V8. Reported by Google on 2026-07-09
[N/A][532931962] Medium CVE-2026-87468: Incorrect authorization in Isolated. Reported by Google on 2026-07-09
[N/A][532952073] Medium CVE-2026-87563: Origin validation error in Paint. Reported by Google on 2026-07-09
[N/A][532957878] Medium CVE-2026-87510: Improper input validation in FileAPI. Reported by Google on 2026-07-09
[N/A][533070113] Medium CVE-2026-87435: Information leak in ControlledFrame. Reported by Google on 2026-07-09
[N/A][533597592] Medium CVE-2026-87531: Information leak in CORS. Reported by Google on 2026-07-11
[N/A][534863145] Medium CVE-2026-87637: Use after free in Extensions. Reported by Google on 2026-07-14
[N/A][536423794] Medium CVE-2026-87529: Numeric truncation error in Media. Reported by Google on 2026-07-19
[N/A][536446354] Medium CVE-2026-87470: Improper quantity validation in Tint. Reported by Google on 2026-07-19
[N/A][536598187] Medium CVE-2026-87586: Out of bounds read in ANGLE. Reported by Google on 2026-07-19
[N/A][537466493] Medium CVE-2026-87584: Incorrect authorization in WebUI. Reported by Google on 2026-07-21
[TBD][538197156] Medium CVE-2026-87632: Cross-site scripting in SanitizerAPI. Reported by Eli Ainhorn on 2026-07-24
[N/A][539569491] Medium CVE-2026-87528: Type confusion in Rust. Reported by marcobartoli on 2026-07-27
[N/A][540015493] Medium CVE-2026-87623: Observable discrepancy in DOM. Reported by Google on 2026-07-28
[N/A][540021850] Medium CVE-2026-87566: Observable discrepancy in Layout. Reported by Google on 2026-07-28
[N/A][540024134] Medium CVE-2026-87638: Out of bounds write in Media. Reported by Google on 2026-07-28
[N/A][542565481] Medium CVE-2026-87455: Use after free in Aura. Reported by Microsoft on 2026-08-04
[TBD][543938457] Medium CVE-2026-87591: Incorrect authorization in Extensions. Reported by antoniosmr02 on 2026-08-07
[N/A][544484669] Medium CVE-2026-87526: Use after free in Passwords. Reported by shab on 2026-08-10
[N/A][547322272] Medium CVE-2026-87609: Use after free in Sharing. Reported by Google on 2026-08-16
[TBD][547592631] Medium CVE-2026-87610: Incorrect authorization in Omnibox. Reported by Arni Hardarson (Neonix Security) on 2026-08-17
[N/A][553155590] Medium CVE-2026-87626: Incorrect authorization in DeviceBoundSessionCredentials. Reported by Google on 2026-08-26
[$1,500][490773579] Low CVE-2026-87629: Incorrect authorization in Sources. Reported by lebr0nli of National Yang Ming Chiao Tung University, Dept. of CS, Security and Systems Lab on 2026-03-08
[$500][40058710] Low CVE-2026-87653: UI misrepresentation in FullScreen. Reported by Lijo A.T on 2022-02-07
[N/A][349994197] Low CVE-2026-87634: Use after free in WebPackaging. Reported by Google on 2024-06-28
[N/A][497025031] Low CVE-2026-87429: Missing authorization in ServiceWorker. Reported by Google on 2026-03-27
[N/A][497203958] Low CVE-2026-87618: Incorrect reference resolution in Storage. Reported by Google on 2026-03-28
[N/A][497359396] Low CVE-2026-87614: Incorrect authorization in ServiceWorker. Reported by Google on 2026-03-29
[N/A][497433347] Low CVE-2026-87619: Observable discrepancy in Prefetch. Reported by Google on 2026-03-29
[N/A][499217288] Low CVE-2026-87561: Incorrect authorization in Web Authentication. Reported by Google on 2026-04-03
[N/A][499218516] Low CVE-2026-87598: Incorrect authorization in ServiceWorker. Reported by Google on 2026-04-03
[N/A][501763003] Low CVE-2026-87519: Incorrect authorization in Safebrowsing. Reported by Google on 2026-04-11
[N/A][502452118] Low CVE-2026-87543: Missing authorization in Core. Reported by Google on 2026-04-14
[N/A][507219126] Low CVE-2026-87522: Missing authorization in WebView. Reported by Google on 2026-04-28
[N/A][513143955] Low CVE-2026-87568: Improper input validation in Chromium. Reported by Google on 2026-05-14
[N/A][513245072] Low CVE-2026-87656: Improper state validation in Safebrowsing. Reported by Google on 2026-05-14
[N/A][513395384] Low CVE-2026-87511: Missing authorization in DevTools. Reported by Google on 2026-05-15
[N/A][513473551] Low CVE-2026-87627: Interpretation conflict in Safebrowsing. Reported by Google on 2026-05-15
[N/A][513726466] Low CVE-2026-87595: Server-side request forgery in Mobile. Reported by Google on 2026-05-16
[N/A][513947572] Low CVE-2026-87592: Out of bounds read in Tint. Reported by Google on 2026-05-17
[N/A][514489101] Low CVE-2026-87620: Observable discrepancy in SVG. Reported by Google on 2026-05-19
[N/A][515426792] Low CVE-2026-87502: Confused deputy in Fullscreen. Reported by Google on 2026-05-21
[N/A][516965176] Low CVE-2026-87448: Use after free in DevTools. Reported by Google on 2026-05-27
[N/A][517219513] Low CVE-2026-87459: Observable discrepancy in Select. Reported by Google on 2026-05-27
[N/A][517776674] Low CVE-2026-87463: Incorrect authorization in Certificate. Reported by Google on 2026-05-29
[N/A][517926950] Low CVE-2026-87546: Incorrect type conversion or cast in Safebrowsing. Reported by Google on 2026-05-29
[N/A][522399466] Low CVE-2026-87538: Clickjacking in Input. Reported by Google on 2026-06-10
[N/A][523243507] Low CVE-2026-87545: Information leak in Mobile. Reported by Google on 2026-06-12
[N/A][523442920] Low CVE-2026-87617: Use after free in DevTools. Reported by Google on 2026-06-13
[N/A][532933816] Low CVE-2026-87523: Race condition in DataTransfer. Reported by Google on 2026-07-09
[N/A][532968511] Low CVE-2026-87565: Information leak in Passwords. Reported by Google on 2026-07-09
[N/A][533018632] Low CVE-2026-87597: UI misrepresentation in CustomTabs. Reported by Google on 2026-07-09
[N/A][533044125] Low CVE-2026-87624: UI misrepresentation in Passwords. Reported by Google on 2026-07-09
[N/A][533084499] Low CVE-2026-87605: Missing authorization in Contacts. Reported by Google on 2026-07-09
[N/A][533112829] Low CVE-2026-87490: Information leak in Transactions Platform. Reported by Google on 2026-07-09
[N/A][533116484] Low CVE-2026-87583: UI misrepresentation in Passwords. Reported by Google on 2026-07-09
[N/A][535718578] Low CVE-2026-87509: Incorrect authorization in Updater. Reported by Google on 2026-07-16
[N/A][537101736] Low CVE-2026-87473: Incorrect authorization in FileHandling. Reported by Google on 2026-07-21
[N/A][537470182] Low CVE-2026-87461: Information leak in Core. Reported by Google on 2026-07-21
[N/A][537476242] Low CVE-2026-87631: Missing authorization in DOM. Reported by Google on 2026-07-21
[TBD][538715523] Low CVE-2026-87469: Improper input validation in Extensions. Reported by Jeong Woo Lee (@eclipse07077) on 2026-07-24
[N/A][539453394] Low CVE-2026-87489: Memory corruption in V8. Reported by Google on 2026-07-27
[N/A][540013886] Low CVE-2026-87575: Incorrect authorization in Loader. Reported by Google on 2026-07-28
[N/A][540046516] Low CVE-2026-87571: Improper certificate validation in Loader. Reported by Google on 2026-07-28
[N/A][540059211] Low CVE-2026-87477: Information leak in Core. Reported by Google on 2026-07-28
[N/A][540070236] Low CVE-2026-87551: Improper certificate validation in CORS. Reported by Google on 2026-07-28
[N/A][540072282] Low CVE-2026-87608: Improper certificate validation in FedCM. Reported by Google on 2026-07-28
[N/A][540082621] Low CVE-2026-87437: Information leak in Frames. Reported by Google on 2026-07-28
[TBD][541546782] Low CVE-2026-87602: Out of bounds read in ANGLE. Reported by Hyeongeun Ji of JeroScope on 2026-08-01
[TBD][541604100] Low CVE-2026-87601: Race condition in V8. Reported by Salvatore Gulizia (nickname: Serotav) on 2026-08-01
[TBD][542355360] Low CVE-2026-87544: Incorrect authorization in Extensions. Reported by antoniosmr02 on 2026-08-04
[TBD][542449805] Low CVE-2026-87430: Buffer overflow in WebRTC. Reported by k-kyuno on 2026-08-04
[N/A][553252820] Low CVE-2026-87593: Information leak in Editing. Reported by Google on 2026-08-27
Google is aware that an exploit for CVE-2026-87491 exists in the wild.
We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.
Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.
Introduced a shared localization module for built-in and curated AMO-hosted theme names, and updated the corresponding about:addons theme test to expect the new “Default” theme name shown when Nova is enabled – Bug 2055936 / Bug 2058235
Added a message bar to the about:addons themes picker to surface AMO-hosted Nova theme download and install failures instead of failing silently – Bug 2054548
WebExtensions Framework
Fixed a startup race where an extension’s restored dynamic content scripts could be missing from the parent WebExtensionPolicy due to stale shared data – Bug 2058719
WebExtension APIs
Fixed publicSuffix.isKnownSuffix() to reject invalid domain-name characters, including wildcard suffixes, that could previously be matched as a known public suffix – Bug 2059819
Fixed the frameId reported by webRequest events for requests made from workers, including importScripts()-loaded scripts, which were previously attributed to the wrong frame – Bug 2048884
Thanks to Giulio B for the fix to webRequest frameId attribution for worker requests.
Standard8 adjusted the source docupload task, that runs on code review, to report failures into phabricator, rather than having a generic error message.
Irene Ni standardized New Tab widgets and sections header spacing (standardize spacing) to remove misaligned tiles and reduce visual jitter when resizing or toggling sections in the New Tab Page.
Mike Conley removed version-153 train-hop compatibility shims for the World Cup newtab logo variations (remove compatibility shims), an internal cleanup that prevents legacy logo-selection fallbacks from influencing current logo variations.
Maxx Crawford exposed available browser themes to New Tab and added apply/install actions (expose and apply themes), allowing users to install or immediately apply themes from the New Tab surface via ThemeManager/Theme API hooks.
Maxx Crawford added New Tab Customize Panel browser theme selection strings (add theme selection strings) so the new theme-selection UI is localized and displays correct labels across locales.
Maxx Crawford added a full browser theme selection sub-panel to the New Tab Customize Panel (theme selection sub-panel) to let users browse, preview, and pick themes directly inside the New Tab customization flow.
Scott Downe fixed Custom newtab wallpapers flash / blink some seconds after loading newtab by ensuring the custom wallpaper is painted only after image data is ready, which removes the multi-second visual flash on about:newtab for users with custom backgrounds and improves perceived stability during initial new-tab load.
Maxx Crawford exposed trainhopConfig values in Discovery Stream Admin tooling, giving operators direct access to trainhop routing/weight values from the admin UI/API so content trains and experiment routing can be adjusted without code deploys—this has no immediate end-user UI change but reduces time-to-rollout for Discovery Stream content changes.
Dre fixed Newtab custom wallpapers flash when selecting from picture of the day widget by deferring the wallpaper swap until the selected Picture of the Day is decoded and ready, which prevents the transient blank/flash users saw when changing wallpapers via the widget and makes wallpaper selection feel instantaneous and stable.
Today, we're excited to take you to Whistler, one of British Columbia's most famous mountain destinations, coming to our upcoming British Columbia DLC for American Truck Simulator!
Located along the scenic Sea-to-Sky Highway north of Vancouver, this vibrant resort town is surrounded by towering peaks, dense forests, and breathtaking alpine landscapes that make every journey through the region unforgettable.
Whistler is world-famous for its outdoor recreation and winter sports, attracting visitors from around the globe year-round. Nestled among the towering peaks of British Columbia's Coast Mountains, it gained international recognition as a host community during the 2010 Winter Olympic and Paralympic Games. Today, the area is renowned for its expansive ski terrain, scenic hiking trails, and impressive network of gondolas and cable cars, which provide breathtaking views of the rugged mountain landscape that surrounds the town.
Our map team has worked hard to capture the unique atmosphere of Whistler, from its distinctive mountain-town architecture to the spectacular scenery that surrounds it. Whether you're delivering supplies to local businesses or simply passing through on your way across British Columbia, this town offers plenty to admire from behind the wheel.
With stunning views around every corner and a rich history tied to one of Canada's most memorable sporting events, Whistler is sure to become a favourite stop for many virtual truckers exploring the British Columbia DLC.
26.3 Pre-Release 3 (known as 26.3-pre-3 in the launcher) is the third pre-release for Java Edition 26.3, released on September 8, 2026, which fixes bugs.
Full changelog: https://minecraft.wiki/Java_Edition_26.3-pre-3
Beta versions are not guaranteed to work as expected. We encourage users to create detailed bug reports if any problems arise. Read our blog post for more information about our Android beta programs.
🌟 Highlights
Add option to always burn in subtitles when transcoding #4459, by @GertSallaerts
Experimental support for MariaDB Connector (C). To use, put libmariadb.dll in hMailServer\Bin. hMailServer will prefer it over libmysql.dll if both exists.
IMAP improvements
Removed the ImapAuthAllowPlainText legacy option
Fixed invalid "Recent" count in IMAP notifications
Fixed FETCH not honoring the start.size partial-fetch clause
DKIM improvements
DKIM signatures for domain aliases
DKIM-sign all email sent from a domain, not just per-account
Fixed signing failure for messages >10MB
DKIM verification when the published DNS record is a CNAME
Signing for NDR/bounce messages
Optional X-Original-Rcpt-To header for incoming mail.
IMAP improvements: RFC 6154 support - LIST extension for Special-Use Mailboxes (\Sent, \Drafts, \Junk, \Trash, etc.), including auto-creation of special-use folders on account creation.
The DistroWatch news feed is brought to you by TUXEDO COMPUTERS. The FreeBSD project has published an update to FreeBSD's 14.x series. The new version, 14.5, provides several fixes and introduces some changes to the userland utilities. "The rc.firewall script now supports reading IP addresses or subnets from on-disk files for the firewall_allowservices and firewall_trusted list variables. Elements that....
Added configurable alerts when scheduled database backups missed a set number of days. #11433 closed #11425.
Streamed S3-only volume archives directly to S3 so those backups no longer needed temporary local disk space. #11642
Added an instance setting for the CDN URL used to serve stored images such as profile avatars and project icons.
Improvements
Refreshed the UI with WCAG-compliant contrast, a unified surface system, a full-height settings rail, and a rebuilt mobile navigation drawer. #11659 closed #11532.
Preserved in-progress domain edits across refreshes, stacked domain rows on small screens, and moved preview deployment settings onto the Previews page.
Paginated service backup history, showed S3 destination details, disabled Backup Now unless the database was running, added search on server resources, and let operators enable Sentinel from its logs page.
Fixes
Allowed General application settings to be saved when an existing domain used a wildcard. #11683 closed #11641.
Prevented duplicate Coolify Cloud subscription checkouts and recovered subscriptions after missed or out-of-order Stripe webhooks. #11666
Preserved PATH in terminal sessions so SSH proxy commands such as cloudflared worked. #11638 closed #11611.
Stopped the persistent storage PR suffix dropdown from clipping inside the volumes table. #11637 closed #11605.
Returned scheduled task execution duration as a JSON number so the CLI could parse listings. #11636 closed #11616.
Persisted S3 storage settings when creating a new volume backup schedule. #11635 closed #11627.
Cleaned up preview deployments when a pull request closed after its base branch changed. #11634 closed #11609.
Persisted the Make publicly available setting for service databases. #11633 closed #11345.
Restored webhook delivery for always-send notifications, including SSL renewal, API token expiry, server force-enable/disable, and Hetzner deletion failures. #11528 closed #11507.
Raised nginx request header buffers so large Cookie headers no longer returned HTTP 400 before reaching Coolify. #11404 closed #11403.
Kept modal contents intact across Livewire re-renders instead of dropping the body and leaving a click-blocking overlay. #11294
Routed Docker Compose domains using each service's ports, stored explicit ports as overrides through the API, and stopped multi-service Compose domains from inheriting the application port.
Applied the same domain validation rules to the service API as the UI, including wildcards and oversized URLs.
Limited instance public IP DNS hints to the localhost server so remote servers showed their own addresses.
Preserved shell negation in sudo-wrapped commands on servers that use a non-root SSH user.
Deferred inspection of PostgreSQL custom-format backup archives to pg_restore so valid dumps were not rejected.
What's Changed
fix(notifications): add missing toWebhook methods to notifications by @ousamabenyounes in #11528
fix(docker): raise nginx request header buffers above the 8k default by @bosund in #11404
fix(service): persist service database public access by @peaklabs-dev in #11633
We are pleased to announce the latest stable release of Jellyfin, version 12.0! This major release brings many new features, improvements, and bugfixes to improve your Jellyfin experience. As always, please ensure you take a full backup before upgrading!
Before upgrading from an earlier version, a full backup of the data directory is strongly recommended, as this release includes database changes that prevent rolling back without a full restore.
Direct upgrades from 10.10.7 and 10.11.x to 12.0 are supported; intermediate upgrades are not required. Users running releases older than 10.10.7 are strongly encouraged to upgrade to 10.10.7 before migrating to 12.0.
Installed repository plugins (anything not built-in) should also be removed before migrating. Plugins will likely need time to adapt to the new database changes, so re-adding them afterward is the safest approach for testing.
Official plugins compatible with Jellyfin are available through the stable plugin repository. If you have changed to the unstable plugin repository please change it back.
We're running a full path-based check on all library items to clean up left overs. Depending on size this can take some time
Alternative versions of media that were auto resolved (not manually merged) will be removed due to data type issues -> A full library scan will fix this again and is therefore REQUIRED AFTER UPGRADE
First scan will take significantly longer than normal and some movies might appear as newly added due to type issues that got fixed on-scan
Multiple versions for episodes
Similarity & recommendation providers
Search providers, letting plugins extend or replace how search results are produced
SchedulesDirect and EPG refresh fixes
Fixes to the parental rating system
Proper data pruning on file replacement/deletion
Support triple+ digit episode numbers
Add library-specific BoxSet and Playlist filtering, allowing per-library collection and playlist views
CACHEDIR.tag support
Accept-Language header support
Add VideoRotation profile condition for Android TVs that do not support rotation metadata
Parse provider IDs from season and episode folder/file names
Allow tmdb, tvdb, and imdb as aliases for the tmdbid, tvdbid, and imdbid provider IDs
Add curly brace and parentheses support for parsing attribute values
Add NameStartsWith and NameLessThan filters to Person search
Add new filters for audio and subtitle languages
Add OriginalLanguage as option to PreferredAudioLanguage
Add a collection API for Included In feature
Add support for VobSub subtitle streams
Add Tmdb missing episode provider
Breaking and behavior changes
Legacy route prefixes removed (/emby/* and /mediabrowser/*). Old third-party clients that rely on them will stop working
Legacy authorization is now disabled by default, and a migration disables it on existing installs as well
Removed obsolete API routes: POST /Users/{userId}/EasyPassword (the EasyPassword feature is gone), GET /Items/{itemId}/CriticReviews, GET /Environment/NetworkShares, POST /System/MediaEncoder/Path, GET /LiveTv/Recordings/Groups/{groupId}, and GET /QuickConnect/Initiate
The global subtitle configuration has been removed, subtitle settings are configured per library
.ogg is no longer treated as a video extension and is audio only, .aifc is now recognized as audio, and .aiff is no longer treated as an image
Symlinks are only resolved at playback time
Sorting by name now uses SortName and CleanName, and the same cleaning logic is applied to ForcedSortName. Library ordering may change compared to 10.11
Image endpoints no longer upscale beyond the source resolution, so low resolution artwork renders at its real size instead of being enlarged
Username capitalization can now be changed. Usernames are stored in a normalized column with a unique index, so installs with usernames that differ only by case need to be corrected before upgrading
Database and performance
Playlists and collections are now properly relational, using a new LinkedChildren table instead of serialized child lists. OwnerId and PrimaryVersionId are real GUID foreign keys, and ExtraIds has been dropped
Many tuning migrations covering item counts, item names, type and clean name, latest items, image info, and primary version id
Migration routines clean up existing data on first boot: duplicate music artists and people are merged, orphaned extras and external data are removed, incorrect owner relationships are repaired, and clean names, forced sort names, and series presentation keys are recomputed
Heavy database tasks no longer run while a library scan is in progress
Faster queries for Resume, Next Up, rewatching, Latest Items for music, playlists and collections, artist lookup, and item counts
Item deletion is batched, which fixes "too many SQL variables" failures when deleting large numbers of items
jellyfin.db can now be stored at a custom path
Operations
New --mode startup flag with MediaServer, MigrateSystem, and SeedSystem, allowing migrations or database seeding to be run without starting the server. This is useful for containerized and orchestrated deployments and for controlled upgrades
The startup interface has been restyled and now shows version and activity information
Disabled plugins are no longer re-enabled on restart
Full system backups skip corrupt keyframe rows instead of failing
Media and subtitles
Subtitle writing now goes through SubtitleEdit, which is what avoids the SSA to ASS conversion and loss of styles
External subtitles can be embedded into MKV when transcoding
The subtitle extraction timeout is now configurable
Client-rendered graphical subtitles are allowed during remux
Fixes for races in concurrent subtitle conversion, cache invalidation when a subtitle is replaced, and ffmpeg hangs during extraction
New HlsAudioSeekStrategy configuration option
Trickplay: existing files are discovered during a scan, duplicates from interlaced video are fixed, invalid PTS values from containers are normalized, and the cache is cleaned up after a failure
Live TV
Live TV no longer returns unreachable "server-local" streaming URLs to clients
XMLTV background images and episode thumbnails are now imported
XMLTV guide imports skip programs whose data has not changed, using an ETag computed from the fields the server actually consumes, which makes repeat guide refreshes considerably cheaper. Other listings providers stay on the existing field-by-field update path
Metadata and providers
ListenBrainz is now bundled with the server and provides similar artist data with a selectable similarity algorithm
TVDB provider IDs are supported for movies
AudioDb artist search
ReplayGain album gain is parsed
MusicBrainz lookups are more resilient
WEB-DL release tags are recognized in file names
Hyphenated numbers in episode titles are no longer parsed as multi-episode files
3D format detection works when the tag is the last token of the path
Person metadata refreshes are queued instead of blocking the request
Transcoder
New upstream version of FFmpeg 8.1
Optimized CUDA transposing filter performance
Optimized OCL scaling filter performance
Optimized OCL tonemapping filter performance on Mali GPU
Use EOTF from BT 2446 Method B for HLG tonemapping
Fix potential A/V desync in HLS when transcoding video while remuxing audio
Avoid SSA to ASS conversion and loss of styles
Add spec-compliant dvh1 HLS variant for DoVi P5 for compatibility
Web
The Modern layout is now the default, the previous layout is now called Legacy
Updated Music Videos view
Updated Mixed Media view
Updated Collections & Playlists view
Updated Books view
Add still watching prompt
Add delay setting for photo slideshow
Add caching of queries to indexed db for the tanstack query client for improved loading performance
Add watch feature to log viewer
Add , and . as controls to scrub frame-by-frame
Add filters for audio and subtitle languages (modern layout only)
Add Collections and playlist tab to all libraries
Add collections to item details page
Replace libpgs with libbitsub and adds support for vobsub rendering
Merge cards for crew with multiple roles
Layout and themes
All themes now derive from a shared base theme built on CSS variables, including Dark, Light, WMC, Blue Radiance, Apple TV, and Purple Haze. Custom themes may need to be adjusted
The library toolbar has been merged into the app bar, with a sticky library header and design polish throughout the library
Custom links can be added to the Modern layout
The screensaver time setting is now available in the Modern layout
Libraries and browsing
Collections and folders tabs for book libraries, and a folder view in the Modern home videos layout
Default tab options for Home Videos and Photos libraries
Studio search, and an extended Studios tab
Play All and Shuffle buttons on the series library. Both are disabled rather than hidden when no items are available
Improved Upcoming view
Sorting and filtering on the Activity page
A Reset Filters button in the filter dropdown
Folders can be marked as played
TV show creators are shown on item details
Similarity providers can be configured per library
Pagination controls are hidden when paging is disabled
Playback
The playback info overlay is more compact and shows more detail
Chapter names are shown in the OSD slider bubble
Bitrate detection now runs in web
Dolby Vision in MKV on webOS 25 and newer
AV1 fMP4 stream copy on TV clients
Direct play of anamorphic video on Tizen, and loosened anamorphic restrictions for browser device profiles
On iOS, background playback continues when the screen is turned off, and audio normalization is disabled to fix pitch and speed issues
libbitsub updated to v1.11.0 with an HLS offset fix
The screensaver is suppressed while viewing photos or reading
TV and remote
Game controller navigation fixes, and the gamepad repeat rate is no longer tied to framerate
Keyboard controls work on non-Latin keyboard layouts, with additional fixes for older browsers
Rewind and FastForward play state commands are handled
SyncPlay menu update, and the SyncPlay ping is now reported to the server
Focused and checked checkbox styling in the TV layout
Under the hood
WebSockets have been migrated to SDK subscriptions
The React and TypeScript migration continues with the libraries, Live TV, and networking pages, and the dashboard user pages now use the TS SDK
TanStack Query now backs user settings and home screen sections, and the query cache is cleared when the server restarts
Notable fixes
Blurry card images on high DPI displays, and card image sizes are rounded up
Duplicate /socket connections
Login loop, connecting to the wrong server when several are configured, and native shell server selection when signing out
An invalid request for all items on page load
The Live TV default landing tab
Holding and dragging on media no longer activates multi-select
A warning is shown before restoring a version, a warning is shown when starting a backup while a scan is running, and a library scan starts automatically when folders are added to a library
Security
Server:
Path validation has been added to the legacy HLS segment endpoints and to the plugin image endpoint, so a requested file must resolve inside the transcode directory
Path traversal hardening has been extended to the image and plugin endpoints and to username path handling, building on the fixes released in 10.11.x
The startup wizard can no longer be re-run without authentication on a misconfigured server
Unsafe plugin package names are rejected by the plugin installer
Parental filtering is enforced on additional endpoints, playlist visibility has been corrected, non-admin access to additional parts has been fixed, and people are exempt from the allowed tags visibility check
Web:
Cross-site scripting via person roles
Auth parameters are encoded when creating API clients
The login disclaimer only allows common link protocol schemes
Books
Books have often taken a backseat in favor of video playback in Jellyfin, but this should no longer be the case.
We have started a concerted effort to improve book support across the API and our official clients.
eBook and comic support is still maturing, but the ODPS plugin allows for direct access from a wide range of popular self-hosted programs.
Correspondingly, contributions in any repository are extremely welcome from the wider community.
That includes server improvements, documentation changes, and third-party clients for book playback.
A combination of eBook, comic, and audiobook support is available on the following clients.
One notable omission from the server is book series as unique entities, which didn't make the cut for this release.
If you would like to bridge the gap until they are added, feel free to use the Folio plugin to display them as collections.
It functions very similar to the TMDb Box Sets plugin but only applies to eBooks.
Another in-flight feature is audiobook chapters, which are only available from the API at present.
Luckily, this means client support is now possible, so you should see them appear in your favorite audiobook client before our next server release.
NOTE: The Bookshelf plugin has been deprecated and its features have been merged into server or extracted into the ComicVine and GoogleBooks providers.
Server Changes
Bookshelf has been split into separate GoogleBooks and ComicVine providers
Local book parsing has been improved and is available without plugins
Book metadata is extracted directly from OPF and ComicInfo files or ComicBookInfo comments
External covers are now supported for audiobook files
Posters are generated for EPUBs and all supported comic archives
Name, index, year, and series are parsed from book filenames
Both volume and chapter will be available in the API when present in comic filenames
Page counts are extracted from comic archives and PDFs
Creator names from OPF data are normalized to a common format
A new OpenLibrary plugin has been created for metadata and images
ISBN external IDs and links are supported
Chapters are now extracted from audiobooks
Web Changes
Modern book library layout has been added with view types and paging
Books display information about their authors and vice versa
Playback interface has been redesigned and standardized across all book types
Progress indicator is enabled again for supported eBooks
Sorting books by index number, release date, etc is now available
Font size selection has been improved for EPUB files
Background audiobook playback is working on iOS devices
Authors, collections, and folders tabs have been added to book libraries, and audiobooks appear under authors
Fullscreen behavior is unified across all book players, and PDFs support swipe navigation
Developers
API Changes
The API no longer allows the use of deprecated authorization mechanisms by default.
Clients and tooling need to migrate if they haven't done so already. See #15559 for details.
There have been a number of other changes to the SDK libraries and API as part of an ongoing effort to better document the API for client use.
Please note the following with regards to API support.
A full explanation of our policy for API changes will be added to the developer documentation in the coming months.
If an endpoint isn't listed in the OpenAPI specification it should not be used by clients.
There are certain endpoints that are still exposed for legacy reasons despite being excluded from the OpenAPI spec.
These can be removed in any major release without warning
If an endpoint or parameter is marked as obsolete in the OpenAPI specification it should not be used by clients.
Same explanation as above.
As a general rule, any deprecations will be marked as such for an entire (major) release cycle before the deprecated endpoint or parameter is liable for removal.
Behavior changes clients should be aware of:
GetItems is now asynchronous and applies recursive when filters are requested, limited to requests that include includeItemTypes. The same query can return a different result set than it did on 10.11
ItemByName responses are restricted and people are deduplicated
Newly obsolete but still functional, with replacements:
GetTrailers -> use GetItems with includeItemTypes=Trailer
GetArtists and GetAlbumArtists -> use GetPersons
GetArtistByName -> use GetPerson
GetMusicGenre -> use GetGenre
GetInstantMixFromMusicGenreById and GetInstantMixFromMusicGenreByName -> use GetInstantMixFromItem
GetStartupConfiguration, UpdateInitialConfiguration, and SetRemoteAccess -> use the configuration endpoints
GetRecordingsSeries
UserDto.HasPassword is marked obsolete and no longer provides useful information
The HLS controllers are hidden from the specification
Platform
The server now targets .NET 10. Plugins have to be retargeted and rebuilt
Swashbuckle has been updated to v10, which changes the generated OpenAPI document, so SDKs need to be regenerated
jellyfin-web now builds with Node 24 LTS and npm 11
Plugin changes
ISearchEngine has been replaced by ISearchManager, and SearchEngine has been replaced by SearchManager together with SqlSearchProvider
Removed: NowPlayingQueueFullItems, DtoExtensions.AddClientFields, Jellyfin.Extensions.AlphanumericComparator, the ISubtitleWriter family of subtitle writers, and SubtitleOptions with SubtitleConfigurationFactory
ServerConfiguration.EncoderPreset is no longer nullable
IAuthenticationProvider.HasPassword has been removed
IPasswordResetProvider.StartForgotPasswordProcess takes the entered username and a nullable user
IUserManager: the Users and UsersIds properties are now the GetUsers and GetUsersIds methods, and RenameUser, ResetPassword, and ChangePassword take a user id instead of a User. GetFirstUser has been added
Several IItemRepository members moved to the new services: item saving and deletion and UpdateInheritedValues to IItemPersistenceService, counts to IItemCountService, and Next Up series keys to INextUpService
IPeopleRepository.GetPeople and ILibraryManager.GetPeopleItems return a QueryResult, and IDtoService.GetBaseItemDtos and ILibraryManager.DeleteItemsUnsafeFast have new signatures
IDirectoryService.GetFilePaths no longer takes a sort argument, and the IPathManager subtitle and attachment path getters are now nullable
New plugin APIs
This release adds several extension points that plugins could not hook into before.
Search providers. Plugins can now take part in search itself rather than only in metadata lookup. ISearchProvider exposes Name, Type, Priority, and CanSearch(SearchProviderQuery), with IInternalSearchProvider for providers that search the local library and IExternalSearchProvider for providers that stream SearchResult items from a remote service. Providers are registered through ISearchManager.AddParts and are consulted in priority order, so a plugin can extend or take over from the built-in SqlSearchProvider
Similarity and recommendation providers.ISimilarItemsProvider is split inherited by ILocalSimilarItemsProvider, IRemoteSimilarItemsProvider, and IBatchLocalSimilarItemsProvider, each with a generic variant so a provider can declare the item type it handles. Providers are selected and ordered per library through LibraryOptions.SimilarItemProviders and SimilarItemProviderOrder, and ISimilarItemsManager also pulls movie recommendations. The bundled ListenBrainz provider is built on this
Comic metadata providers.IComicProvider (ReadMetadata and HasItemChanged) lets a plugin supply comic metadata alongside the built-in ComicInfo and ComicBookInfo readers
Chapters for any item type.IChapterManager.SaveChapters now takes a BaseItem rather than a Video, and gained a Supports(BaseItem) check. This is what makes audiobook chapters possible, and it lets plugins save chapters for non-video items
Password resets for unknown users.IPasswordResetProvider.StartForgotPasswordProcess now receives the entered username along with a nullable user, so a provider can handle a request for a username the server does not know or hand the reset off to an external provider
Media segment cleanup.IMediaSegmentProvider.CleanupExtractedData is called when an item's data is pruned, so segment providers can remove their own extracted files
Schedules Direct.ISchedulesDirectService exposes available countries, service availability, and the image daily limit state, so Live TV plugins no longer need to reimplement them. ITunerHostManager.DeleteTunerHost allows removing a tuner
Alternate versions and linked children. Now that linked children are relational, ILibraryManager exposes ResolveAlternateVersion, GetLocalAlternateVersionIds, GetLinkedAlternateVersions, GetItemIdsWithAlternateVersions, and UpsertLinkedChild. Plugins that manipulated version links through serialized item data need to move to these
Batch APIs for bulk work.IUserDataManager gained GetUserDataBatch, GetResumeUserData, GetResumeUserDataBatch, and ResetPlaybackStreamSelections. ILibraryManager gained GetPeopleByItems, GetPeopleNamesByItems, and GetNextUpEpisodesBatch. IItemCountService offers batched child and played/total counts
Localization.ILocalizationManager.GetServerLocalizedString and GetLanguageDisplayName let plugins localize against the server locale
ICollectionManager.GetCollectionsContainingItem backs the Included In feature, and IPlaylistManager.AddItemToPlaylistAsync takes a position so items can be inserted at the top of a playlist
IHasEmbeddedImage is also new, but it is only for plugins compiled into the server; external plugins should keep declaring their image with imagePath in meta.json.
TLS Configuration
In the previous release notes 10.11.0 we announced the deprecation of the built-in TLS certificate handling for this version. This change has been postponed to a future version.
This release addresses medium-impact problems that need to be fixed as some enable remote DOS or SMTP smugggling.
The fixes below, and more, are also released in the unstable version postfix-3.12-20260902.
In addition to updated releases for the supported Postfix versions 3.8-3.11, releases will also be available for the out-of-support Postfix versions 3.5-3.7. NOTE: these do not include the patches for out-of-support Postfix versions that have been issued for "large SMTP inputs (June 2026)", and for "TLSA parsing (June 2026)". Those patches still need to be applied.
These defects were found by "Qualys assisted by Claude Mythos Preview", and by "OpenAI Security"; three date from 20 or more years ago.
As suggested by OpenAI Security, eliminate stray CR characters from the smtpd_proxy_filter input stream. The before-proxy-filter SMTP server already eliminated stray LF.
Bug (introduced: Postfix 3.11, date: 20250917): SMTP smuggling was possible with smtpd_proxy_filter (disabled by default) when the before-filter SMTP server added a "Require-TLS-ESMTP: yes" message header, due to implementation edge cases. Adding this header is enabled with the "requiretls_esmtp_header = yes" default setting. Reported by OpenAI Security. Fix by Wietse.
Server crashes and panic()s:
Bug (defect introduced: Postfix 3.0, date: 20140707): null pointer read error after receiving MAIL FROM, RCPT TO, and VRFY with an UTF8 address but no SMTPUTF8 parameter. This requires "smtputf8_enable = yes" (the default) and "strict_smtputf8 = yes" (not default). With this, the SMTP server did an unnecessary MAIL FROM reset without RCPT TO reset. A crafted remote SMTP client could then send a DATA command and crash a Postfix SMTP server process with a null pointer read error. Reported by Wonyoung Jung (정원영).
Other bugs
Bug (defect introduced: Postfix 3.4, date: 20180303): the MySQL client setting "tls_verify_cert = yes" had no effect with Oracle MySQL 8 and later. Report and fix by OpenAI Security.
Bug (defect introduced: Postfix-beta, date: 19990119): the pipe(8) delivery agent deleted a command-line argument if the argument contained $user AND $user expanded to an empty string, breaking the positional order of arguments. This was a workaround for a problem that hopefully no longer exists. Reported by Qualys, assisted by Claude Mythos Preview.
Bug (defect introduced: Postfix 2.3, date: 20050323): the SMTP client enhanced status code parser could process stale data when a remote SMTP server sent a three-digit reply without other text. Reported by Qualys, assisted by Claude Mythos Preview.
TLS
Isolation: stamp Postfix SMTP server TLS session tickets with their master.cf service name. With this, an SMTP server defined in master.cf will no longer accept tickets issued by a different SMTP server defined in the same master.cf file. Fix by OpenAI security.
Configuration safety
The postmap and postalias commands now log a warning when creating a root-owned database file in a directory that is not owned by root. They log that the database source file, indexed file(s), and parent directory should have the same owner, to prevent a privilege-escalation attack. Problem reported by OpenAI Security, remediation strategy (don't break production deployment) by Wietse.
Read after free, memory over-read
Bug (introduced: Postfix 2.3, date: 20060629): a malicious Milter or attacker-in-the-middle could trigger a null-terminated heap memory overread in the SMTP daemon while formatting a malformed multiline response. Fix from OpenAI Security adopted with minor changes.
Bug (defect introduced: Postfix 3.0, date: 20141117): in the postqueue command don't free() text before logging a fatal error message. Reported by Qualys, assisted by Claude Mythos Preview.
Code hygiene: in the SMTP client protocol engine, evaluate a RETURN() macro argument before freeing resources. Reported by Qualys, assisted by Claude Mythos Preview.
Code hardening (defense in depth, prevention)
(Postfix 3.11) Hardening: in the non-BerkeleyDB migration service, delay the decision between running postmap or postalias until after the database file/directory owner/permission checks. The benefit from making the decision early (better error messages) was not worth the risk. Qualys, assisted by Claude Mythos Preview.
(Postfix 3.11) Hardened the database parent directory permission checks for automatic re-indexing with the non-Berkeley-DB migration service.
Hardening command-line email submission: the postdrop command now disallows null and line-break characters in queue file envelope records (line-break characters in non-envelope queue file records are already neutralized by default with "cleanup_replace_stray_cr_lf = yes").
The new constraint not only eliminates line-break injection into local mailbox files as reported by OpenAI Security, but also prevents other forms of misuse. Later, this constraint may be moved into the Postfix core. Fix by Wietse.
Shut up nagging from multiple AIs and harden the virtual delivery agent against an evil (LDAP or SQL) database.
Code hygiene: myrealloc(ptr, 0) still resulted in a panic. Reported by Qualys, assisted by Claude Mythos Preview. Also adopt a mystrndup() fix from Postfix 3.12.
Other:
Portability: OpenBSD does not define NS_INT16SZ. Brad Smith.
Welcome to the capital city of the Mount Rushmore State, Pierre! In today's blog, we will be sharing a preview of our version of this beautiful town and its sister city, Fort Pierre, which are eagerly waiting to welcome their first truckers with the imminent release of the South Dakota DLC.
While being a relatively small town with just around 14,000 residents, Pierre is a hidden gem waiting to be explored. Welcoming nearly 3 million visitors each year, it is a destination for outdoor enthusiasts, offering world-class fishing, scenic trails, and endless opportunities for water recreation. This is made possible by its location along the banks of the Missouri River, set between Lake Oahe and Lake Sharpe, both created by dams.
But it's not just outdoor activities that draw visitors to Pierre. The city is also home to plenty of stunning historic landmarks, some of which we have recreated in our map. One of them is the South Dakota State Capitol Building, constructed in 1910. Keep an eye out for this architectural gem when driving through the city, as it can be spotted from a distance.
When arriving to the Pierre area from the south, you'll first pass through Fort Pierre, the oldest established settlement in the state, dating back more than 200 years. Here, you'll be able to spot a school building featuring a beautiful bison mural, as well as Fort Volunteer, a fort built to honor the volunteers who came to help during the 2011 flood.
Across from it, you'll find the courthouse with its stone monument featuring another bison. Further down the road, you'll also be able to spot the Casey Tibbs Rodeo Center Museum up on the hill, which is a multipurpose conference center and historical museum dedicated to the legendary sport of South Dakota rodeo.
Then, crossing the Missouri River over a newly built bridge, you'll be greeted by the "Welcome to Pierre" sign, followed by the Discovery Center building, an interactive, hands-on science museum for families and children.
And if you are driving to Pierre not just for sightseeing, but also to pick up a job, there are also plenty of industries that will need your help transporting their products, such as the shopping center, landscape supplies, and roadwork depots. We have also included the Pierre Airport on the outskirts of the city into the map, where you will be able to deliver cargo to and from. On the other side of the river in Fort Pierre, you will find a local truck dealer, livestock auction, mining machinery service, and truck stop depot.
Don't forget to follow us on X/Twitter, Facebook, Instagram, Bluesky, and YouTube for all the latest news from this map expansion and other American Truck Simulator content, or sign up for our newsletter to stay informed. Until next time, we will see you on the road!
The DistroWatch news feed is brought to you by TUXEDO COMPUTERS. This week in DistroWatch Weekly:
Review: Genuen 6.0.0
News: Multikernel Linux, bots swarm the kernel repository, Debian being deployed at CERN, Debian 11 reaches its end of life
Questions and answers: Avoiding LLM-written code
Released last week: Linux From Scratch 13.1, Grml 2026.09, Talos Linux 1.14.0, Zenwalk GNU Linux 260905, NetBSD....
If you are using Part-DB it would be helpful if you fill out this short survey on your usage of Part-DB (Google Forms): https://forms.gle/Q15twx3YYq3qCNfe8
Part-DB 2.17.0
New features
Support stateless MCP version 2026-07-28, alongside old stateful versions, improved MCP metadata
Added an advanced part search MCP tool, for more detailed part searches
From the 14th to the 20th of September, members of our team will once again be heading to Hannover, Germany, for IAA TRANSPORTATION 2026, one of the world's leading events for logistics, commercial vehicles, and the transport industry.
Having attended IAA in previous years, we’re excited to return in 2026 and meet with many of our friends and partners from across the automotive industry. We’ll also be working alongside a few of our valued partners to bring our truck simulation experience to the DAF Trucks, MAN and Scania booths throughout the event!
At the Scania booth, visitors will have the opportunity to experience a special Euro Truck Simulator 2 demonstration running on Scania's own motion simulator setup. Our team has been happy to work closely with Scania to develop the software and a specially prepared demo experience for their simulator, and we're looking forward to seeing visitors get behind the virtual wheel and try it out for themselves during the show.
Our friends at DAF and MAN will also both be bringing Euro Truck Simulator 2 to their booths, as we're lending them our very own 4D motion simulators, giving visitors another opportunity to experience our virtual trucking world. We're very happy to support our partners at DAF & MAN for this year's event and to see our motion rigs become part of their presence at the show.
Attending IAA is much more than what visitors will see on the show floor for us. Bringing together manufacturers, suppliers, technology providers, and many other representatives from across the transport industry makes an event of this scale an invaluable opportunity for our team.
Throughout the week, we plan to meet with a number of our existing partners, continue building the relationships which help us bring the world of trucking into Euro Truck Simulator 2 and American Truck Simulator, and hopefully make some new connections along the way. Events such as IAA also provide our teams with a valuable opportunity to research the latest developments within the transport industry, see new vehicles and technologies up close, and gather useful references and knowledge for our future work.
We're very much looking forward to returning to Hannover and meeting so many familiar faces from across the industry. If you're attending the event yourself, be sure to stop by and check out the simulators; or if you happen to spot some of our team attending, wearing a SCS Software, ETS2 or ATS T-shirt, be sure to stop them and say hello!
As always, keep an eye on our social media channels for updates from the show floor, as we will be bringing you some cool photos from the event. We hope to see some of you there! Until till next time, keep on truckin'!
If you are upgrading from v0.16.x, replace the binary (or run docker pull). If you are upgrading from v0.15.x and below, please read the upgrading documentation for more information on how to upgrade from previous versions.
Added
Changed
Sieve: Messages generated by user scripts are DKIM signed through the new SieveUserInterpreter.dkimSignDomain setting, which defaults to the account's own domain.
Fixed
JMAP:
CalendarEvent/set requests that ask for scheduling messages are rejected with a forbidden error when the account cannot send them.
Calendar/get and AddressBook/get return every property when the properties argument is omitted or null.
EventSource ping events advertise the interval in seconds rather than milliseconds.
Calendar synthetic ids returned when expanding recurrences identify an occurrence by its recurrence id.
IMAP: Every command in a pipelined STATUS or FETCH batch receives its tagged completion, instead of the first failing command dropping the responses for all commands queued behind it.
WebDAV: Accounts without a storage quota no longer advertise a 4 GiB limit in DAV:quota-available-bytes.
MTA: Inbound DMARC and TLS aggregate reports that a reporter sends more than once are imported again as a duplicate entry.
Spam filter: Domain and URL blocklists are queried only for text written as a link.
iTIP: Detaching an occurrence that the recurrence rule already generates is sent as a METHOD:REQUEST carrying the RECURRENCE-ID instead of a METHOD:ADD.
Sieve: fileinto :specialuse and specialuse_exists accept special-use attributes in the \Trash form.
LDAP: Active Directory servers that answer an unauthenticated bind (a non-empty DN with a zero-length password) with success no longer authenticate accounts without a password.
Network: Listeners bound to the unspecified IPv6 address ([::]) fall back to IPv4 when socket creation fails with EPROTONOSUPPORT.
OpenTelemetry: log exporter does not include the parent span's attributes.
The DistroWatch news feed is brought to you by TUXEDO COMPUTERS. The NetBSD project has announced the fifth and final update to the NetBSD 9.x series. The NetBSD 9 series will no longer receive security updates. "Announcing NetBSD 9.5. Note: this will be the final release from the netbsd-9 stable branch and also marks the end-of-support for this branch.....
Fixed Cloudflare AI Gateway routing for third-party providers so non-Workers models work through the gateway's REST API. (@superhighfives)
Fixed Anthropic models through Cloudflare AI Gateway by converting dotted model IDs like claude-haiku-4.5 to the dashed slug Anthropic expects. (@superhighfives)
Fixed parent session IDs being sent in request headers for session-aware providers.
TUI
Bugfixes
Fixed GitHub auth for immutable OIDC subject tokens.