Mozilla sent Firefox Version 90.0 to the release channel today. The update includes eight security updates of which five (5) are rated high and four (4) are rated moderate.
Firefox ESR was updated to Version 78.12.
High
- #CVE-2021-29970: Use-after-free in accessibility features of a document
- #CVE-2021-29971: Granted permissions only compared host; omitting scheme and port on Android
- #CVE-2021-30547: Out of bounds write in ANGLE
- #CVE-2021-29976: Memory safety bugs fixed in Firefox 90 and Firefox ESR 78.12
- #CVE-2021-29977: Memory safety bugs fixed in Firefox 90
Moderate
- #CVE-2021-29972: Use of out-of-date library included use-after-free vulnerability
- #CVE-2021-29973: Password autofill on HTTP websites was enabled without user interaction on Android
- #CVE-2021-29974: HSTS errors could be overridden when network partitioning was enabled
- #CVE-2021-29975: Text message could be overlaid on top of another website
New
- On Windows, updates can now be applied in the background while Firefox is not running.
- Firefox for Windows now offers a new page about:third-party to help identify compatibility issues caused by third-party applications
- Exceptions to HTTPS-Only mode can be managed in about:preferences#privacy
- Print to PDF now produces working hyperlinks
- Version 2 of Firefox’s SmartBlock feature further improves private browsing. Third-party Facebook scripts are blocked to prevent you from being tracked, but are now automatically loaded “just in time” if you decide to “Log in with Facebook” on any website.
Changed
- The "Open Image in New Tab" context menu item now opens images and media in a background tab by default. Learn more
- Most users without hardware accelerated WebRender will now be using software WebRender.
- Improved software WebRender performance
- FTP support has been removed
Update
To get the update now, select "Help" from the Firefox menu, then pick "About Firefox." Mac users need to select "About Firefox" from the Firefox menu. If you do not use the English language version, Fully Localized Versions are available for download.
References
Release Notes
Rapid Release Calendar
No comments:
Post a Comment