Release notes
These release notes are summaries of the most important changes for public releases.
Published 2026-09-24
UXP Changes:
- Implemented the
URL.Parse() convenience
function.
- Added multiple bounds checks on internal browser functions
to avoid potential out-of-bounds accesses, underflows and overflows. (DiD)
- Fixed several issues with loading and parsing
content-supplied fonts.
- Set a bottom limit on the frequency for audio samples to
avoid a whole class of potential bugs surrounding audio loading,
processing and playback.
Audio formats with a sample rate below 8kHz (the commonly accepted
lowest sample rate of "telephone"/"walkie-talkie" quality) are now
rejected.
- Fixed a potential issue in CSS rounded corners with dotted
styling.
- Image elements in forms are no longer associated if they
are not in the same subtree.
- Made image animation checks more strict to avoid potential
issues if decoding would be slow.
- Video region checks are now more strict to avoid issues
with malformed video files.
- Implemented the CSS
revert-layer keyword.
- Implemented CSSStyleSheet
replaceSync.
- Implemented the CSS
:has() pseudo class.
- Implemented support for
adoptedStyleSheets.
- Firefox compatibility mode had its version updated to 140
by
default. Of course this can still easily be overridden (globally or
per-site) where necessary.
- JavaScript garbage collection and DOM cycle collection have
been
given a number of important fixes to better deal with heavy modern
websites that would not properly release their resources. The
"ghostbuster" workaround for lingering window objects has been removed
in tandem as it is no longer necessary.
- Removed old and obsolete code from the platform related to
ancient or completely unsupported compile targets.
- The uppercase version of ß (eszett/scharfes S) will now
always mirror the lowercase writing method. See implementation notes.
- Added more updates for LoongArch64 (including full JIT) and
Mac/PPC support.
- Linux/FreeBSD: Added a GTK2 dependency toggle to build
NPAPI support without GTK2. This allows Basilisk to build plugin
support on systems with no GTK2 packages.
- Removed the unused "network tickler" module, an inherited
component that could ping wireless networks on a regular interval.
- Modernized
std::*<T>::value/::type to
their _v and _t suffix forms, respectively,
aligning with more modern C++ language standards and compiler behavior.
- Updated CSS
aspect-ratio to be more
spec-compliant.
- Updated flex container buttons to report a definite size
(avoiding 0-sized elements on some websites).
- Restored the ability to compile Basilisk on MIPS targets.
- Fixed an issue with possible hangs in recursive restyling
calls (causing a recursive reflow storm), avoiding potentially long
browser hangs/lockups.
- Updated several parts of the ICU code for better
internationalization support.
- Linux: Improved typing performance on some complex pages.
- Partial support for ARM64/aarch64 JIT. ARM64 builds will run substantially as of this release.
- Fixed potential undefined behavior in float to int32
conversions.
- Made checking for structural errors in XML-based files more
strict.
- Fixed a crash in the
WeakRef implementation.
- Fixed a potential issue in UI tooltips (DiD).
- Fixed a regression in XSLT transformations that would
result in incorrect output.
- Updated the internal json viewer for better handling of resources.
- Updated NSS to 3.90.14.0 (UXP) addressing all applicable
security issues from NSS upstream.
- Another large security audit of over 200 sec bugs in
Mozilla land has been performed, with the vast majority not being
applicable to our code base (primarily e10s/IPC bugs).
- Security issues addressed: CVE-2026-16353, CVE-2026-16408,
CVE-2026-16389 CVE-2026-74982, CVE-2026-74969 (DiD), CVE-2026-74977 (DiD), CVE-2026-74945, CVE-2026-74964, CVE-2026-74971, CVE-2026-74943, CVE-2026-92016 (DiD), CVE-2026-92044, CVE-2026-92049, CVE-2026-92030, CVE-2026-92012, and many others that do not have a CVE designation.
Basilisk Changes:
- Added Intl.RelativeTimeFormat polyfill
- Introduced MIPS64EL Linux Builds. Please note that these have only been tested on Loongson 3A4000 MIPS hardware and may fail on other MIPS hardware due to differences in a few CPU opcodes between Loongson MIPS and other MIPS CPUs. They are also built on a fairly bleeding edge Linux distribution (AOSC) and so may not work on older versions of Linux for MIPS64EL.
- Built on UXP commit: e59e88bfd5
Included Polyfills:
-
This release includes the following polyfills:
- image.decode
- Intl.DisplayNames
- Intl.RelativeTimeFormat
- Intl.Segmenter
- en-US only Intl.ListFormat
- Microsoft-specific (Outlook, Azure, etc) webauthn shim
- TestDecoderStream
- TextEncoderStream
- TransformStream
- ReadableStream pipeTo
- ReadableStream pipeThrough
- getAnimations
- elementFromPoint finite values
UXP Implementation Notes:
- Primarily in German, the ß character (known as "eszett" or "scharfes S") can be written with its proper character or with the alternative latinized "ss". Because the uppercase version of ß was not commonly included in system fonts for a while, with historical typewriter conventions in mind, converting text to uppercase would convert ß to "SS". However, this can cause ambiguity in some wordswhere both a spelling with ß and with "ss" exist which have different meaning. Since the uppercase unicode character has been included in system fonts for a long time now and is more commonly also included in custom fonts, this conversion is an old notion. The linguistic bodies in Germany also prefer using the uppercase ẞ now when capitalizing, so Basilisk will use the unicode character by default going forward when converting case (e.g. with CSS or JavaScript), abandoning the on-the-fly conversion to "SS".
- Our FreeBSD GTK3 builds are making use of the new option to build NPAPI support without GTK2 dependencies. If you need this functionality on FreeBSD, either use the GTK2 binaries or build from source yourself with the appropriate configuration for your system.
Old Releases
Old release notes from Basilisk Development Team releases can be found
here.
Release notes from releases by Moonchild Productions can be found
here.