Official release of 'Firefox 95' with updates such as strengthening countermeasures against supply chain attacks and appearing in the Microsoft Store



The official version of the web browser ' Firefox 95' has been released. In addition to Firefox appearing in the Microsoft Store of Windows, a new technology called 'RL Box' has been adopted as a countermeasure against supply chain attacks that introduce vulnerabilities into the libraries used in Firefox.

Firefox 95.0, See All New Features, Updates and Fixes

https://www.mozilla.org/en-US/firefox/95.0/releasenotes/

◆ Reduced battery consumption when playing movies on macOS
Reduced energy consumption when software decoding movies such as Netflix and Amazon Prime Video, especially when playing full screen.

◆ Firefox is now available in the Microsoft Store
Firefox is now available in the Microsoft Store for Windows 10 and Windows 11 and is easy to install.



◆ New security technology 'RL Box' is adopted
When executing content in the browser, we utilize a unique sandboxed process to minimize the impact of vulnerabilities. Furthermore, in recent years, updates have been made to further reduce the scope of impact by separating processes for each site, but on the other hand, there was a vulnerability in the third-party library used in Firefox. The measures in the case were limited. Similar to site isolation, using a method of separating processes by component of code has the disadvantages of degrading performance due to asynchronous execution and increasing memory usage, so the process isolation approach is It has only been adopted by some large components such as audio processing and movie processing.

RLBox adopted in Firefox 95 makes it possible to minimize the effects of vulnerabilities in third-party libraries that could not be covered by the above countermeasures. Instead of running the code in a separate process, you can compile it into WebAssembly once and then compile it into native code to prevent jumps to other parts of the program and access to out-of-bounds memory. It will be possible to share the address space safely.

◆ Picture-in-picture button can be moved to the opposite side
You can now move the 'Watch in Picture in Picture' button displayed in the movie to the left. Right-click the button to display the menu, so click 'Move the picture-in-picture switch button to the left'.



◆ Site separation enabled for all users
Site isolation is now enabled for all users as a defense against side-channel attacks such as Specter.

◆ Update for developers
· ' Inputmode ' is supported on all platforms

-Implemented ' Cryptocurrency.randomUUID () ' function
A 36-character fixed-length UUID is generated.

Firefox 95 also includes a number of security fixes.

The next major version, Firefox 96, will be released on January 11, 2022 local time.

in Software, Posted by log1d_ts