With the release of our South Dakota DLC, we invite you all to join us on Thursday, the 24th of September, for the newest World of Trucks event - Cruising South Dakota! Roll through the Mount Rushmore State and take in its wide-open landscapes, natural beauty and rich history.
So, what is the challenge? Haul cargo to or from any city in South Dakota and help the community reach a collective goal of 150,000,000 miles (241,402,000 km). With the strength of our #BestCommunityEver, we know you will smash it!
Hit the road by #CruisingSouthDakota, where vast prairies meet the rugged Black Hills and the otherworldly Badlands, with long crossings over the Missouri River along the way. But this land carries far more than scenery, it holds stories that reach deep into the past. The Black Hills, known to the Lakota people as Paha Sapa, are sacred ground, while Badlands National Park preserves one of the richest fossil beds on Earth. This is where giants like SUE the T. rex slept for millions of years before being discovered.
During your travels, you can look forward to many spectacular views and highlights, such as:
Mount Rushmore National Memorial, the iconic monument carved into a granite face in the Black Hills.
Badlands National Park, a dramatic maze of layered rock spires and buttes unlike anywhere else in America.
Deadwood, the legendary gold rush town where Wild Bill Hickok played his final hand.
Missouri River crossings, where the great river divides the rolling east from the rugged west of the state.
As with past Cruising events, you can also participate using your own trailer by selecting jobs from the External Market!
The South Dakota DLC features 13 incredible cities to explore, and we're offering an exclusive reward for completing your personal goal, which will require you to deliver a job to or from all of them. All jobs for the event must be at least 100 miles (161 km) long.
Take part in this breathtaking journey across the Great Plains, from South Dakota's sweeping landscapes and Black Hills to its frontier towns. Let's roll through the Mount Rushmore State!
Rules
Using External Contracts or External Market, with a World of Trucks-connected profile in American Truck Simulator, the community goal is to drive 150,000,000 miles (241,402,000 km) while delivering cargoes to or from any city in South Dakota.
When a player has completed deliveries to or from all 13 South Dakota cities, they will achieve their personal goal.
All jobs for the event must be at least 100 miles (161 km) long.
You can check if your recent deliveries met these conditions using your Log Book in your World of Trucks profile.
Rewards
Personal: Players who complete deliveries to or from all 13 South Dakota cities will earn a personal World of Trucks Achievement and a Call of the Badlands ATS truck paint job Steam inventory item.
Community: When the community goal of driving 150,000,000 miles (241,402,000 km) during deliveries to or from any city in South Dakota is met, players who have also achieved their personal goal will receive a Ring-necked Pheasant Steam inventory item.
Note: In order to qualify for the community reward, you must complete your personal goal in American Truck Simulator. Each reward will be a Steam inventory item for American Truck Simulator. Once completed, claim your rewards on the Events page of your World of Trucks profile.
The event will conclude on Sunday, the 22nd of November at 23:59 UTC.
Gear up for the latest addition to American Truck Simulator and join us for #CruisingSouthDakota! Share your screenshots and videos with us on our Facebook, X (formerly Twitter), and Instagram profiles, and we will share our favourite ones (we may even feature some of them in a future blog post!).
Pre-release. This is a test build for Bulwark Lite. Not recommended for production. The latest Docker tag stays on 1.10.0. To try the server build, use ghcr.io/bulwarkmail/webmail:1.11.0-beta.1.
Bulwark Lite
Bulwark Lite is a static build of the webmail. It has no Node server: the browser talks to your JMAP server directly.
bulwark-lite-1.11.0-beta.1.zip: unpack it on any static web host (nginx, Caddy, S3, Pages…). Set your JMAP server in config.json. The JMAP server must allow CORS from the webmail origin.
bulwark-lite-stalwart.zip: a Stalwart Application bundle. Install it as an Application in Stalwart and it serves itself under the configured prefix (e.g. /webmail).
The Lite zips are attached once the Build Static Lite workflow finishes (a few minutes after publishing).
Please report problems with the Lite build in the issue tracker.
Also in this pre-release
New "Flat fields" theme
Icon set migrated from Lucide to Tabler Icons
Hardened Lite login, deep-link replay and settings gating
In June, we announced that we are working on the Indiana DLC for American Truck Simulator. While our map teams are busy bringing the Hoosier State to life, they first had to experience it for themselves. Let's take a look back at their research trip to Indiana!
The team that set out for Indiana consisted of the map DLC lead Dubak, our map designers Lukáš and Martin, and our researcher Spekin. Today, they will share their impressions from the trip and a couple of photos they captured along the way. Below, we are also bringing a few screenshots from the work-in-progress map!
"This was my second research trip to the US, and every time it's an incredible experience for me. It boasts not only amazing nature and landscapes, but also rich and beautiful cities. Before the trip, we were a bit worried that Indiana would be a state full of fields, but we were completely wrong. It was a great experience, and I'm really glad that my team and I get to build this wonderful state and show players all the beauty and hidden gems Indiana has to offer," Dubak told us.
They travelled across the state, visiting many of its cities and landmarks, from Indianapolis to Fort Wayne, Evansville, South Bend, and more. "We were blown away by the memorial and the Capitol in Indianapolis, and we also checked out a massive steel mill in East Chicago, Lake Monroe, and the Indiana Dunes National Park," Dubak said.
During their nine-day journey, the team gathered plenty of references and experienced the atmosphere of each place they visited. They explained that walking the streets and visiting these places in real life before recreating them in the editor was a completely new experience.
"As a map designer, I was thrilled to have the opportunity to visit the US in person. You can feel the atmosphere and the scale of everything around you. Personally, I enjoyed all the landmarks in Indiana - from courthouses and churches to banks, statues, historical monuments, memorials, and murals, not to mention the small details here and there. History has shaped the US greatly, and you have the opportunity to experience that," Lukáš shared with us.
Being there in person also reveals smaller details that can be difficult to notice through street view or other sources. This helps the team understand what is important to include in the game and what gives each place its authentic feel.
"As a map designer, I looked for all the details that make every corner authentic. If you are sufficiently attentive, you can find a lot of interesting stuff around. For example, I learned that bigger is better. You can hardly go wrong with that. I also love discovering all the different advertisements, billboards, and signs. I created a large photo gallery of them so that our branding and asset team could use them as inspiration for the state of Indiana and upcoming projects. We also saw an Amish community in the region, which was really interesting. Overall, the research trip was a great experience, and I would love to come back for more inspiration," Lukáš said.
For Martin, it was the diversity of Indiana's landscapes and the roads connecting them that made the biggest impression.
"I was amazed by how diverse the landscape actually is, with plenty of forested areas that transition into national parks, wetlands, prairies, and even sand dunes up north along Lake Michigan. What captivated me the most was probably the scenic IN-46 highway between Bloomington and Columbus. The road winds through the Norman Upland, home to Indiana's largest state park, Brown County State Park. We drove through many towns packed with truly memorable landmarks. In the capital, Indianapolis, it was fascinating to see modern skyscraper architecture blending with historic buildings, churches, cathedrals, and beautifully maintained parks," Martin shared with us.
Even Spekin was surprised by some of the things he saw during the trip, despite his role as a researcher, which means he spends a lot of time studying upcoming DLC areas and preparing references for the rest of the team.
"I was shocked by how big everything is in the US. For example, flags, totems, grain bins, or even roads and countryside are not as straight as they seem on street view, and you can also see the elevation. We observed and measured everything from a random curb in the city to grown corn in the countryside, so the biggest task was just not to look suspicious while capturing those details," he told us.
As a researcher, Spekin records everything that could be useful to other departments and considers how these references could be used in the game, while keeping our scale and other map limitations in mind: "Sometimes a reference can be just for inspiration, like night photos of buildings with neon lights or backlit advertisements, which are often difficult to find. During the trip, however, this was much easier, as we often arrived at our final destination late at night," he shared.
"It might sound weird, but I like farm areas, so grain elevators, barns, and animals are my favorite ones, so you can probably guess what my photo library looks like. I also love industrial zones, so I really enjoyed Gary Steel Works, even though we saw it only from the outside. We also visited a few old covered bridges in Indiana, and I know it's just an old bridge, but I liked it a lot. Of course, I enjoyed the whole trip, every city and every town. I wish we could put everything into the game," Spekin says.
While our work on the map is still in its early stages, we also wanted to give you a small preview of what's already getting done.
Here, you can see a few locations that are taking shape for the Indiana DLC, including the public library in Evansville, Acy Lake, and locations around Indianapolis and along I-69 and US 30.
And that's it from today's blog! We hope you have enjoyed this report from our research trip to Indiana. If you are looking forward to exploring the Hoosier State like we did, be sure to add the Indiana DLC to your Steam wishlist and show your support to our team working on it!
Device addresses can now be configured using a fully qualified domain name instead of an IPv4 address. UpSnap resolves regular hostnames through DNS and .local hostnames through mDNS before pinging, waking, shutting down, or putting a device to sleep.
Changelog
Others
9f05b1c: Docker - add line in compose for dbus if using fqdn with .local domain (#1772) (@invario)
b17b091: feature: Support use of FQDN resolution with DNS and mDNS (#1760) (@invario)
Added a read-only API endpoint to retrieve preview deployment runtime logs by application UUID and pull request ID, with line limits and optional timestamps. (#11884)
Fixes
Fixed deployment status and metadata processing when remote command output contained leading or trailing whitespace.
What's Changed
feat(api): expose runtime logs for preview deployments by @andrasbacsai in #11884
The Stable channel has been updated to 153.0.8010.52/.53 for Windows andMac and 153.0.8010.52 to Linux which will roll out over the coming days/weeks. A full list of changes in this build is available in the Log
Security Fixes and Rewards
Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.
This update includes 16 security fixes. Please see the Chrome Security Page for more information.
[TBD][500417361] Critical CVE-2026-93374: Use after free in Dawn. Reported by Florian Schweitzer on 2026-04-08
[N/A][548085797] Critical CVE-2026-93372: Buffer overflow in WebGL. Reported by Google on 2026-08-17
[$3,000][550839154] High CVE-2026-93375: Incorrect reference resolution in Tracing. Reported by M. Fauzan Wijaya (Gh05t666nero) on 2026-08-22
[TBD][541707261] High CVE-2026-93382: Use after free in PDFium. Reported by WinD39 - Huynh Dinh Vu on 2026-08-02
[N/A][553130676] High CVE-2026-93387: Improper state validation in Skia. Reported by Google on 2026-08-26
[N/A][553132214] High CVE-2026-93373: Use after free in Extensions. Reported by Google on 2026-08-26
[TBD][556853443] High CVE-2026-93381: Buffer overflow in PDFium. Reported by SeungMyung Lee (@sm1ee), Siung kim (@ksw9722) on 2026-09-03
[TBD][560039872] High CVE-2026-93379: Incorrect authorization in ORB. Reported by OGINOME Tomohito on 2026-09-11
[N/A][560121552] High CVE-2026-93377: Type confusion in V8. Reported by Google on 2026-09-11
[N/A][498411599] Medium CVE-2026-93380: Race condition in FileSystem. Reported by Google on 2026-04-01
[N/A][511832293] Medium CVE-2026-93384: Server-side request forgery in Omnibox. Reported by Google on 2026-05-10
[N/A][515493668] Medium CVE-2026-93383: Information leak in Permissions. Reported by Google on 2026-05-22
[N/A][520521197] Medium CVE-2026-93376: Out of bounds read in DataTransfer. Reported by Google on 2026-06-05
[N/A][540051167] Medium CVE-2026-93378: Missing authorization in Storage. Reported by Google on 2026-07-28
[N/A][553136980] Medium CVE-2026-93385: Information leak in Paint. Reported by Google on 2026-08-26
[N/A][513996595] Low CVE-2026-93386: UI misrepresentation in WebAppInstalls. Reported by Google on 2026-05-17
We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.
Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.
The Extended Stable channel has been updated to 152.0.7977.134for Windows and Mac which will roll out over the coming days/weeks.
A full list of changes in this build is available in the log. Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.
On Friday, September 18, Apple Store locations around the world introduced customers to the iPhone 18 Pro lineup, Apple Watch Series 12, Apple Watch Ultra 4, and AirPods 5.
This release fixes six vulnerabilities reported by Jan Kahmen (turingpoint). Please update.
Mail: HTML mail could run script in the webmail origin. cid: references were rewritten to blob: URLs that kept the sender's Content-Type, and the reverse proxy skipped every security header — CSP included — on app paths whose last segment contains a dot, although the signed-in mail, calendar, contacts and files routes render there. Blob URLs are now retyped as inert, link clicks from the message frame are gated by scheme, and the proxy only skips headers for an explicit static-asset allowlist (GHSA-xvjh-v9c6-qcvc, thanks @kah-ja)
Auth: POST /api/auth/session and POST /api/auth/stalwart-context minted identity cookies without checking the supplied credentials against the JMAP server, so anyone could obtain a cookie for an arbitrary username and read that user's server-side settings. Credentials are now verified upstream before a cookie is issued: Basic credentials are bound to the account they authenticate, Bearer tokens to the session's username and identity. Deployments whose webmail container cannot reach the JMAP server no longer receive identity cookies, so cross-device settings sync stops working there (GHSA-wxcm-j4jc-9fxq, thanks @kah-ja)
Plugins: The /plugin-sandbox runtime trusted whichever window posted the first message, so a foreign site could window.open() it, post its own init, and run code under the route's unsafe-eval CSP in the app origin — with or without plugins enabled. The sandbox now only accepts its framing window, and the proxy refuses to serve the route outside an iframe or when plugins are disabled (GHSA-96cx-gx36-3g79, thanks @kah-ja)
Auth: Encrypted payloads now carry a purpose, so a WOPI editor access token can no longer be presented as a jmap_stalwart_ctx session cookie (GHSA-cqqx-mjcf-mh55, thanks @kah-ja)
Auth: Reject cross-site requests to /api/auth/*. A malicious page could POST the victim's browser into an attacker-controlled account (session fixation) (GHSA-qvr9-m8cq-7wvg, thanks @kah-ja)
Mail: Strip CR/LF and other control characters from the header values of generated read receipts. A crafted, RFC 2047-encoded subject could inject additional headers into the receipt (GHSA-w38p-hpqv-g89c, thanks @kah-ja)
Auth / Branding: Pin the resolved IP at connect time for stored custom JMAP endpoints and branding URLs too, closing the DNS-rebinding gap left after GHSA-24w9-8r42-8jwm
Features
Search: Global search across mail, contacts, calendar and files — query parser, ranking and cross-account providers, a search palette, and a search tab in the Pro shell with avatars, tinted icons and structured previews (#641); hits open through the owning login on every surface (#847)
Files: Office document editing through WOPI — Collabora Online, OnlyOffice and EuroOffice (#425); the demo Files drive ships office document fixtures and a word-processor icon
Calendar: Freely scrolling month, week and day views (#759), infinite scroll in the agenda view, and a setting to turn free scrolling off
Calendar: Recurring occurrences use Stalwart's synthetic ids (#140)
Calendar: Attendee free/busy via Principal/getAvailability
Calendar: Invitations and updates surface from CalendarEventNotification, and invitations are organized as the default ParticipantIdentity
Mail: Per-message HTML / plain-text toggle (#1022)
Mail: Share mail folders with other users via mail:share; share notifications appear as toasts
Mail: Search hits are highlighted with SearchSnippet/get
Mail: Pushes are resolved with Email/changes and Mailbox/changes deltas instead of refetching the list
Mail: Attachments show on list rows and open from there (#947, thanks @shukiv)
Mail: Filter advanced search by message size
Mail: Deleting a non-empty folder offers to delete its messages along with it
Mail: "Clear search when switching folders" setting (#852, thanks @shukiv)
CI: The test suite runs on every push and pull request (#647)
Dev: FileNode and blob round-trip in the mock JMAP server, and WOPI on the same-origin dev server
Changes
Docs: Installer section removed from the README and formatting cleaned up
Security policy: New vulnerability report email address
Fixes
Filters: Render the "Keep" action as fileinto "INBOX" (#1027)
Mail: List tagged mail from every account in the tag view, not just the selected folder's account (#1038)
Mail: Dragging a message out of the list could hang the tab when generated .eml file names collided (#1039)
Mail: Preserve label filtering during mailbox refreshes (#1017, thanks @ctaoist)
Mail: Hide body-embedded cid: parts declared as application/octet-stream from the attachment list (#1005, thanks @dealerweb)
Mail: Stop stretching images that carry their own max-width (#1034, thanks @shukiv), and let sender tables keep theirs (#790)
Mail: Refetch the body when JMAP truncates the displayed part instead of rendering a blank message (#928, thanks @hildebrandttk)
Mail: Auto-detect text direction in the read, print, plain-text, thread and .eml preview views (#663, thanks @shukiv)
Mail: Open search hits from shared folders in the right account (#923)
Mail: Collapse search hits for the same server object reached through several logins (#641)
Mail: Guard quick search against stale responses (#872, thanks @vj1235432)
Mail: Only show the unified mailbox section when it can be populated (#843), and stop it missing accounts that had not connected yet (#959, thanks @hildebrandttk)
Mail: Surface Email/set failures on delete and move (#956)
Mail: Report a missing archive mailbox instead of failing silently (#578), and archive shared-inbox mail into the owner's archive (#889)
Mail: Mark as spam from the viewer after the message left the list (#695)
Mail: Sort folders in the role assignment dropdown (#984)
Mail: Add the missing "Scheduled" folder role label (#495)
Mail: Wire the x shortcut to thread expansion (#683)
Mail: Keep the reading-mode toggle mounted so toolbar buttons stop jumping (#964)
Mail: Stop the batch toolbar hiding the message you just selected (#948, thanks @shukiv), keep rows in place when it opens, and drop the duplicate selection checkbox
Mail: Align the unread dot with the first line (#715, thanks @lucletoffe) and centre the sender avatar against the row (#953, thanks @shukiv)
Mail: Use Simplified Chinese for the selected-messages label (#786)
Send: Send from the address a message was delivered to (#991, thanks @rotterp)
Send: Set the answered flag when a reply goes out with a send delay (#985)
Composer: Upload attachments through the composing identity's account (#943)
Composer: Pro compose tabs default their From to the open mailbox (#990, thanks @rotterp)
Calendar: Jump to the day picked in the mini calendar (#1037, thanks @dealerweb)
Calendar: Wait for the JMAP client before loading the account principal, and recognise a refused principal read by its JMAP error type (#1036, thanks @dealerweb)
Calendar: Dedupe participants, resolve contact names across alias domains, and show the organizer's status (#986, thanks @ibayue)
Calendar: Linkify URLs in the event description (#968, thanks @lucletoffe)
Calendar: Normalize task progress states (#994, thanks @mulatta) and omit progressUpdated from the task completion payload (#958, thanks @sanitz)
Calendar: Preserve task alarms that the edit dialog does not show (#504)
Calendar: Report calendar clear failures instead of counting zero (#434)
Calendar: Make the iCal subscription size limit configurable and show the real error (#692)
Calendar: Paginate the event fetch on import so UID deduplication sees all existing events (#113)
Contacts: Strip the local-account prefix from address-book ids on contact update (#1043)
Contacts: Set name.full on all write paths so vCards carry the mandatory FN (#430)
Contacts: Create new contacts in the selected address book (#940, thanks @ponchofiesta)
Accounts: Detect HTTP/2 from the initial navigation timing so accounts are not capped at five (#1003, thanks @lucamzanon)
Auth: Reject wrong passwords server-side so the browser never shows its Basic Auth dialog (#969)
Auth: Stop retrying token refreshes that fail permanently (#972)
Auth: Normalize the OAuth discovery base so a session JMAP_SERVER_URL refreshes (#971, thanks @thejdubb02)
Auth: Use the selected server's issuer for SSO discovery (#952)
Auth: Retry the JMAP session fetch when a redirect drops the auth header (#892)
Auth: Drop max_age=0 from OIDC re-authentication requests (#938)
Auth: Require a session for the translate API (#903)
Mobile: Keep the actions panel below the status bar and pad attachment preview overlays for the iOS PWA safe area (#936)
Mobile: Render plain-text-only mail as text in the thread view (#489)
Mobile: Stop the More menu flashing open when a message is opened
Mobile: Dismiss the search panel once a search runs, open the folder drawer from the right in RTL (#944, thanks @shukiv), and keep the account switcher header on screen
PWA: Focus the client before navigating on notification click (#914, thanks @bitfactory-dk)
Push: Resolve push previews for shared and group mailboxes (#839)
Plugins: Allow sandbox chunk loading with CORS (#922, thanks @mulatta)
Plugins: Fail fast when the plugin storage database is blocked (#840)
Plugins: Refill missing managed bundles from the server (#636)
Plugins: Translations for plugins installed from the marketplace (#939, thanks @paulhenry46)
Settings: Index newer settings and the flat calendar toggles in the settings search
Settings: Invalidate the persisted update status after an upgrade
UI: Readable native <select> option lists in dark themes (#999)
i18n: German update (#1031, thanks @GyroGearl00se), "Forward as attachment" in more languages (#1016, thanks @dulinux), toolbar keys for nb and zh-TW (thanks @ibayue), and managed sidebar-app keys for zh-TW
i18n: Preserve locale cookie precedence and normalize Chinese proxy locale detection (thanks @kchuang1015); keep basePath when normalizing a Chinese Accept-Language
The DistroWatch news feed is brought to you by TUXEDO COMPUTERS. The Parted Magic project has published a new release. The new version, 26.09, has moved its base from Slackware 15.0 to Slackware's development (Current) branch. The release announcement, available on the distribution's news page states: "There is a new disk cloner in this release. Wipe Free Space has....
The DistroWatch news feed is brought to you by TUXEDO COMPUTERS. The AlmaLinux project has published a new beta snapshot for the 9.x series. "AlmaLinux 9.9 beta introduces new compiler toolsets, new module streams, and improved security. This release adds GCC Toolset 16 alongside updated LLVM and Rust toolsets and brings Node.js 26 and PHP 8.4 as new module....
Donations are appreciated. There is now a PayPal option.
Changes from 2.8.1 to 2.8.2:
Updates:
Updated LAV Filters to version 0.83-5-gd65a9
Updated MPC Video Renderer to version 0.10.8.2587
Changes/additions:
Added ReplayGain support. Options can be found in audio switcher.
Improvements for exclusive mode seekbar when using MPCVR.
Improvements for opening a selection of files from Explorer. Now supports DropTarget interface.
Playback rate can now be shown in statusbar for audio files.
Keyboard shortcuts can now be edited without a mouse. Press Space or Enter to start editing a selected command. Press Enter or Tab to apply a pressed key combination. Enter/Tab can only be set as hotkey when combined with Alt/Ctrl/Shift.
Improvements for ATSC/DVB channel scanning.
Fixes:
Lots of small fixes and improvements.
Full changelog
Full list of all changes since start of this project.
OpenSubtitles download error 406
Subtitle downloads from OpenSubtitles may fail depending on time of day. This is due to our daily download quota being exceeded. Current amount of donations is barely enough to pay for the existing quota. So it is unlikely that quota can be increased and situation will get worse over time.
If you create an OpenSubtitles account and configure it in MPC-HC settings then you may be able to bypass the quota.
Options > Subtitles > Misc > Right-click on OpenSubtitles.com > Setup > Fill in username/password
Overview of features
A lot of people seem to be unaware of some of the awesome features that have been added to MPC-HC in the past years. Here is a list of useful options and features that everyone should know about:
Play HDR video
This requires using either MPC Video Renderer (MPCVR) or madVR.
These renderers can be selected here:
Options > Playback > Output
With other video renderers, the colors will be wrong!
MPCVR is included and is the recommended and default renderer for modern systems. MadVR needs to be installed separately. MPCVR also supports Dolby Vision. MadVR does not.
For optimal performance you should change the hardware decoder to D3D11 in LAV Video Decoder settings when using MPCVR on Windows 10/11, because this renderer uses DirectX11.
The installer of MPC-HC is very basic (and that will not change).
I therefore recommend using K-Lite Codec Pack. That includes MPC-HC and other essential components. It has a very advanced installation that can automatically create file associations, and helps you with easy configuration of important MPC-HC settings, such as preferred subtitle language(s). It also does automatic configuration of renderer and hardware decoding, for best performance and HDR support.
The Standard version should be sufficient for most people. Use Full version of you like to use MadVR.
Modern GUI Theme (Dark or Light) or the old classic theme
Options > Player > User Interface
It is also possible to change the height of the seekbar and size of the toolbar buttons.
Plus there are options to show audio/video details in the statusbar, such as codec and resolution.
Customizable toolbar buttons
You can add/remove/re-order the player buttons.
There are also several different toolbar designs to choose from.
Video preview on the seekbar
Options > Player > User Interface > Hover type
Ability to search for subtitles
Press D for manual search.
Or enable automatic search in: Options > Subtitles > Misc
Adjust playback speed
Menu > Play > Playback rate
The buttons in the player that control playback rate take a 2x step by default. This can be customized to smaller values (like 10%):
Options > Playback > Speed step
If you have 1000 IQ you can even do smart stuff like setting playback rate change to mouse right-click + scrollwheel:
Options > Player > Mouse
Adjusting playback speed works best with MPC Audio Renderer or SaneAR. These audio renderers have automatic pitch correction, while DirectSound does not.
Options > Playback > Output > Audio Renderer
MPC-HC can remember recently played files and also their playback position, so you can resume playback from when you left
Options > Player > History
You can quickly seek through a video with Ctrl + Mouse Scrollwheel.
You can jump to next/previous file in a folder by pressing PageUp/PageDown.
You can right-click on the framestep button to step backwards. Some other buttons also have right-click actions, such as closing file by right-clicking stop.
You can perform automatic actions at end of file. For example to go to next file or close player.
Options > Playback > After Playback (permanent setting)
Menu > Play > After Playback (for current file only)
A-B repeat
You can loop a segment of a video. Press [ and ] to set start and stop markers.
You can rotate/flip/mirror/stretch/zoom the video
Menu > View > Pan&Scan
This is also easily done with hotkeys (see below).
There are lots of keyboard hotkeys and mouse actions to control the player. They can be customized as well.
Options > Player > Keys
Tip: there is a search box above the table.
You can hide GUI elements even in windowed mode
Options > User Interface > Hide Windowed Controls
That hides most GUI elements during playback. To show them simply move your mouse to bottom of window.
You can even hide everything except the video by pressing 1 (restore normal view with 3).
You can seek inside the playlist by simply typing text (when playlist window has the mouse focus).
MPC-HC also supports Blu-ray playback.
Only limitation is that you need to use a decrypting tool.
And it also does not support Blu-ray menus, but you can use the navigate menu in the player to select the content to play.
You can stream videos directly from Youtube and many other video websites
Put yt-dlp.exe in the MPC-HC installation folder.
Then you can open website URLs in the player: Menu > File > Open File/URL
You can even download those videos: Menu > File > Save a copy
Tip: to be able to download in best quality with yt-dlp, it is recommended to also put ffmpeg.exe in the MPC-HC folder.
Several YDL configuration options are found here: Options > Advanced
This includes an option to specify the location of yt-dlp.exe in case you don't want to put it in MPC-HC folder.
Note 1: You also need to install Microsoft Visual C++ 2010 SP1 Redistributable Package (x86)
Note 2: For optimal Youtube support you may also need to put deno.exe in same folder as yt-dlp.
Note 3: yt-dlp nightly build (very latest version made daily)
Note 4: yt-dlp windows7 compatible build
Besides all these (new) features, there have also been many bugfixes and internal improvements in the player in the past years that give better performance and stability. It also has updated internal codecs. Support was added for CUE sheets, WebVTT subtitles, etc.
You should really take a few minutes to look through all the options pages if you are a new user or if you are upgrading from a very old version. Don't forget the advanced options page.
The DevTools team has made it possible to inspect and edit stylesheets from within the JavaScript Debugger pane.
The feature can also be enabled from the experimental section in the devtools settings panel, or by setting devtools.debugger.features.stylesheets-in-debugger to true in about:config.
Restyled the Extensions panel empty states to match the Figma specs, including a new illustration for the disabled add-ons and private browsing states – Bug 2058450
Fixed a jiggle effect when scrolling through theme previews in about:addons – Bug 2059917
Added spacing between message bars and their sibling elements in the about:addons page (empty state promo, theme appearance mode control) – Bug 2066436
Set focus on the extension permissions prompt dialog so keyboard users can reach it – Bug 2059855
Removed activeAddons/activeTheme/activeGMPlugins from the legacy telemetry environment, now collected only through Glean – Bug 2055613
DevTools
Nicolas Chevobbe [:nchevobbe] fixed an issue in the inspector to stop showing the HTML editor for nodes (e.g text or whitespace nodes) which should not be editable when F2 is pressed. (#2064213)
Sebastian Zartner [:sebo] updated the documentation for the Rules view to include details around the @media emulation panel added some weeks back. (#2063851)
Chris Van Linden fixed an styling issue in debugger editor file search bar where the button hover background overlapped the focus outline (#2063466)
Nicolas Chevobbe [:nchevobbe] fixed an a11y issue where the keyboard focused sliders in the fonts panel did not have the correct contrast against the background. This allows keyboard users to easily see which control currently has focus. (#2062576)
There is no automation for the core type updates yet.
However, several areas have been working on support, hence the promotion to tier 2.
Until we get the automation in place, we will not be ready for wider roll-out, as it will be more likely that core patches will break the TypeScript reporting.
New Tab Page
Developer experience improvement: it’s no longer necessary to create the WebPack bundles when updating New Tab JSX / SCSS files. This occurs automatically during the ./mach build [faster] step. Thanks to Nathan Barrett for his work there!
Mike Kaply made it so that New Tab Settings honor Locked Preferences in policy by making the New Tab settings UI read and respect policy-locked preferences and disabling corresponding controls so managed/enterprise users cannot override locked prefs from the settings surface.
Nina Pypchenko [:nina-py] added a small size to the Stocks New Tab widget, introducing a compact 1×1 Stocks tile in the Firefox New Tab Page layout so users on narrow windows or dense NTP configurations can keep Stocks visible without consuming medium/large slots.
Nina Pypchenko [:nina-py] added ticker search to find and add individual stocks, adding a search/lookup UI and add flow that calls the ticker lookup API and updates widget state/local storage so users can search, add, and immediately see new symbols on their New Tab Page.
Bryan Olsson added a plural selector to the Fluent string newtab-stocks-watchlist-full in the New Tab Page localization so the Stocks widget shows correct singular/plural wording for watchlist sizes across locales, fixing grammar that could confuse users when their watchlist count changes and touching the NTP stocks string bundle used by all localized builds.
We’ve also started rolling out an experimental Privacy widget
Reem Hamoui changed the Privacy widget copy color to grey in the New Tab Page so the “Nightly blocks trackers as you browse. You will see them here.” text displays with correct muted contrast (2063205).
Reem Hamoui restored the ETP OFF state rendering in the New Tab Page privacy widget so the widget shows the actual ETP OFF status instead of misleading ‘blocks trackers’ copy for users who disable ETP (2063525).
Reem Hamoui applied UX fixes to the New Tab Page privacy widget to correct alignment, labels, and click-targets so users see and interact with the widget reliably and accessibility attributes behave as expected.
We’ve also started tinkering with some new layout variants
Here’s one such layout (widget column on left):
Irene Ni updated SectionsLayoutFeed’s 7-double-row-2-ad fallback to match Remote Settings so feed layout and ad fallback counts align with remote config, reducing layout mismatches and incorrect ad placements in feeds using the fallback (2063684).
Irene Ni implemented a carousel card type for the New Tab feed, adding slide-based card rendering and navigation hooks so users get swipeable/rotating cards in the carousel component.
Dre cleaned up orphaned wallpapers in the wallpaper service to remove broken entries and reduce wasted storage so users no longer see missing background tiles.
Nina Pypchenko [:nina-py] fixed wallpaper attribution rendering in the Nova New Tab flow by adjusting the Nova-specific NTP component’s conditional rendering (CSS/JS) so the attribution node is not skipped when the nova feature is enabled, restoring photographer/credit metadata on New Tab pages for users on Nova-enabled desktop builds and preventing missing attribution UX.
We’re in early days in building out the infrastructure for a Recent Searches widget
Nina Pypchenko [:nina-py] added a blank widget scaffold to the New Tab Page widget registry for the Search team (bug 2065011), creating a no-op/placeholder widget registration hook so the Search team can iterate on experiments without changing current NTP visuals — no immediate visible impact for end-users until the widget is populated.
Drew fixed alignment of the explanation text on various result types. Bug 2063460
Drew enabled more providers (like Wikipedia) for DE, FR, IT regions. Bug 2064557
Drew updated important dates suggestions for 2027 in DE, FR, GB, IT and US regions. Bug 2064437
Dao fixed a regression with the result menu being empty on certain results. Bug 2066758
Adaptive autofill
James is analyzing results of experiments and working with Product to let the feature ride to Release in the near future.
Quick actions
Dale improved the Open Firefox Labs action. Bug 2063849
Dale improved styling of disabled actions. Bug 2056488
Multi Context Address Bar
Dao and Moritz made great progress with having the urlbar code work in different contexts, including across processes.
Dao migrated some text input context menus (address bar, search bar, Thunderbird compose subject) onto a single shared menu with a new custom-item API, allowing removal of the legacy moz-input-box component.See EditContextMenu for documentation and usage. Bug 2064369.
Dharma started refactoring the urlbar code to use extended classes. Bug 2064728
New tab search bar has been enabled in Nightly! Bug 2062212