Waterfox

BrowsersDesktop

A privacy-focused browser built on Firefox.

Latest 6.6.17 · · Desktopby WaterfoxWebsiteBrowserWorks/Waterfox

Release activity

Release activity — 10 releases across 8 days since Apr 21, 2026. Each cell is one day; darker means more releases that day. Nothing is recorded before Apr 21, 2026. Older weeks are hidden at this screen width.
MayJunJulAug
SundayNo releases on Apr 26, 2026No releases on May 3, 2026No releases on May 10, 2026No releases on May 17, 2026No releases on May 24, 2026No releases on May 31, 2026No releases on Jun 7, 2026No releases on Jun 14, 2026No releases on Jun 21, 2026No releases on Jun 28, 2026No releases on Jul 5, 2026No releases on Jul 12, 2026No releases on Jul 19, 2026No releases on Jul 26, 2026No releases on Aug 2, 2026
MondayNo releases on Apr 27, 2026No releases on May 4, 2026No releases on May 11, 2026No releases on May 18, 2026No releases on May 25, 2026No releases on Jun 1, 2026No releases on Jun 8, 2026No releases on Jun 15, 2026No releases on Jun 22, 2026No releases on Jun 29, 2026No releases on Jul 6, 2026No releases on Jul 13, 2026No releases on Jul 20, 2026No releases on Jul 27, 2026No releases on Aug 3, 2026
Tuesday1 release on Apr 21, 2026No releases on Apr 28, 2026No releases on May 5, 2026No releases on May 12, 20261 release on May 19, 2026No releases on May 26, 2026No releases on Jun 2, 2026No releases on Jun 9, 2026No releases on Jun 16, 2026No releases on Jun 23, 2026No releases on Jun 30, 2026No releases on Jul 7, 2026No releases on Jul 14, 20262 releases on Jul 21, 2026No releases on Jul 28, 2026No releases on Aug 4, 2026
WednesdayNo releases on Apr 22, 2026No releases on Apr 29, 2026No releases on May 6, 2026No releases on May 13, 2026No releases on May 20, 2026No releases on May 27, 20261 release on Jun 3, 2026No releases on Jun 10, 20261 release on Jun 17, 2026No releases on Jun 24, 2026No releases on Jul 1, 20262 releases on Jul 8, 2026No releases on Jul 15, 2026No releases on Jul 22, 2026No releases on Jul 29, 2026No releases on Aug 5, 2026
ThursdayNo releases on Apr 23, 2026No releases on Apr 30, 2026No releases on May 7, 2026No releases on May 14, 2026No releases on May 21, 2026No releases on May 28, 2026No releases on Jun 4, 2026No releases on Jun 11, 2026No releases on Jun 18, 2026No releases on Jun 25, 2026No releases on Jul 2, 20261 release on Jul 9, 2026No releases on Jul 16, 2026No releases on Jul 23, 20261 release on Jul 30, 2026No releases on Aug 6, 2026
FridayNo releases on Apr 24, 2026No releases on May 1, 2026No releases on May 8, 2026No releases on May 15, 2026No releases on May 22, 2026No releases on May 29, 2026No releases on Jun 5, 2026No releases on Jun 12, 2026No releases on Jun 19, 2026No releases on Jun 26, 2026No releases on Jul 3, 2026No releases on Jul 10, 2026No releases on Jul 17, 2026No releases on Jul 24, 2026No releases on Jul 31, 2026No releases on Aug 7, 2026
SaturdayNo releases on Apr 25, 2026No releases on May 2, 2026No releases on May 9, 2026No releases on May 16, 2026No releases on May 23, 2026No releases on May 30, 2026No releases on Jun 6, 2026No releases on Jun 13, 2026No releases on Jun 20, 2026No releases on Jun 27, 2026No releases on Jul 4, 2026No releases on Jul 11, 2026No releases on Jul 18, 2026No releases on Jul 25, 2026No releases on Aug 1, 2026

10 releases since Apr 21, 2026, busiest day 2

Changelog

6.7.0-beta.3

Pre-release
Added 4
  • Extended legacy extension support
  • Added official Linux package repositories with both x86_64 and ARM64 DEB and RPM packages for Ubuntu, Debian, Fedora, and Mageia
  • Added a redesigned About dialog built on the Waterfox design
  • Enabled the global menu bar on Linux desktops that provide one, including on Wayland
Changed 4
  • Re-enabled Ultra Protection by default for new profiles with DNS lookups traveling over Oblivious HTTP through the Waterfox relay
  • Allowed the media cache's in-memory layer to grow with available RAM instead of stopping at a fixed ceiling
  • Restored the View Image Info context menu item
  • Redesigned the macOS disk image as a fully signed and notarised installer image
Fixed 2
  • Opening a link in a new private tab from the context menu no longer opens it in a normal tab instead
  • The major upgrade welcome dialog no longer displays raw label identifiers instead of its text

Waterfox 6.7.0 beta 3 switches Ultra Protection back on, broadens Linux packaging to ARM64 with proper package repositories, and continues restoring legacy extension support.

New
  • Re-enabled Ultra Protection by default for new profiles. DNS lookups travel over Oblivious HTTP through the Waterfox relay, meaning no single party can see both who you are and which sites you look up. Existing profiles can enable it under Settings.
  • Extended legacy extension support.
  • Added official Linux package repositories with both x86_64 and ARM64 DEB and RPM packages. Waterfox can now be installed and kept up to date through the package manager on Ubuntu, Debian, Fedora, and Mageia.
  • Added a redesigned About dialog built on the Waterfox design.
  • Enabled the global menu bar on Linux desktops that provide one, including on Wayland.
Changed
  • Allowed the media cache's in-memory layer to grow with available RAM instead of stopping at a fixed ceiling.
  • Restored the "View Image Info" context menu item.
  • The macOS disk image is a redesigned, fully signed and notarised installer image.
Fixed
  • Opening a link in a new private tab from the context menu opened it in a normal tab instead.
  • The major upgrade welcome dialog displayed raw label identifiers instead of its text.
View originalPermalink
How 6.7.0-beta.3 went

6.6.17

Changed 5
  • Update country based search configuration to use Qwant in supported regions and DuckDuckGo elsewhere, with Qwant as fallback
  • Migrate users from 1.org default and other automatically selected defaults to appropriate regional defaults
  • Remove obsolete search overrides that could interfere with regional defaults or suppress Waterfox search attribution parameters
  • Stop forcing the experimental HTTP Idempotency-Key header on POST requests
  • Proxy search suggestion requests that would go to Google through Waterfox Private Search to prevent direct connection and preserve IP address and request metadata
Fixed 1
  • Attempt to fix Chase website compatibility when Waterfox's built-in content blocker is enabled
Security 1
  • Include fixes covered by Mozilla Foundation Security Advisory 2026-70

Waterfox 6.6.17 includes security fixes from the forthcoming MFSA 2026-70, attempts to correct the previous regional search configuration, and includes compatibility fixes also shipping in the 6.7 beta.

Security

Waterfox 6.6.17 includes the fixes covered by Mozilla Foundation Security Advisory 2026-70.

Changed
  • Updated the country based search configuration:
    • Qwant is used in supported regions.
    • DuckDuckGo is used elsewhere.
    • Qwant remains the fallback while the region is unknown.
  • Migrated users from the former 1.org default, and from other defaults selected automatically by previous configurations, to the appropriate regional default. 1.org is still available as an option, but due to a bug there was no way to separate users who selected 1.org as the default, vs those who have just been following the default.
  • Removed obsolete search overrides that could interfere with regional defaults or suppress Waterfox search attribution parameters. Built-in content blocker conflict handling remains unchanged.
  • Stopped forcing the experimental HTTP Idempotency-Key header on POST requests.
Privacy
  • Search suggestion requests that would otherwise go to Google are now proxied through Waterfox Private Search. This prevents a direct connection between your browser and Google, keeping your IP address and request metadata from being sent to Google directly.
Fixed
  • (Attempted) Fixed Chase website compatibility when Waterfox's built-in content blocker is enabled.
Support Waterfox in 3 different ways

If you would like to support Waterfox's continued development, you can do so through either of the project's search options or by helping test upcoming releases.

1. Use Qwant and allow search ads

If Qwant is supported in your region, make it your default search engine and consider allowing ads on Qwant search pages. Waterfox's built-in content blocker allows search ads on Qwant by default. If you use another ad blocker, please consider allowlisting Qwant.

Search revenue from Qwant helps fund Waterfox at no cost to you, while Qwant does not track or profile its users. Learn more about the Waterfox and Qwant partnership.

2. Subscribe to Waterfox Private Search

Waterfox Private Search has received a fresh lick of paint. It offers an ad-free search experience through a subscription that directly supports Waterfox's development while keeping privacy at its core.

3. Test Waterfox Beta

Waterfox 6.7.0-beta.2 is available now. Testing the beta on your usual websites and workflows, then reporting anything you find, helps catch regressions before they reach the stable channel.

Visit the download page, select the Beta channel, and choose the build for your platform.

View originalPermalink
How 6.6.17 went

6.7.0-beta.2

Pre-release
Added 2
  • Added initial support for restartless legacy extensions using install.rdf, bootstrap.js, and compatible chrome.manifest entries
  • Enabled publication of prerelease x86_64 DEB and RPM packages through the Waterfox OBS repositories
Changed 3
  • Updated Qwant's regional availability, search parameters, and branding
  • Disabled automatic enforcement of soft-blocked add-ons
  • Disabled automatic generation of HTTP Idempotency-Key headers by default
Fixed 8
  • Improved tree tabs session restoration, undo-close handling, and migration from legacy tree tab settings
  • Corrected child-tab placement and tree ordering
  • Fixed pinning, collapsing, subtree depth limits, and parent-closing behaviour in tree tabs
  • Fixed cross-window drag-and-drop and tab moves initiated by extensions or context menus
  • Prevented selected tabs from remaining hidden inside collapsed trees
  • Refreshed expand and collapse controls with RTL and reduced-motion support
  • Fixed Chase website compatibility when Waterfox's built-in content blocker is enabled
  • Fixed selected Waterfox colour palettes sometimes being overwritten by a later default-theme update

Waterfox 6.7.0 beta 2 expands testing for legacy extensions and Linux packaging while bring tree tabs reliability fixes.

New
  • Added initial support for restartless legacy extensions using install.rdf, bootstrap.js, and compatible chrome.manifest entries. Full support will be restored soon.
  • Enabled publication of prerelease x86_64 DEB and RPM packages through the Waterfox OBS repositories.
Changed
  • Updated Qwant's regional availability, search parameters, and branding.
  • Disabled automatic enforcement of soft-blocked add-ons. Hard-block protections remain active, including for unsigned legacy extensions.
  • Disabled automatic generation of HTTP Idempotency-Key headers by default.
Fixed
  • Significantly improved tree tabs:
    • Improved session restoration, undo-close handling, and migration from legacy tree tab settings.
    • Corrected child-tab placement and tree ordering.
    • Fixed pinning, collapsing, subtree depth limits, and parent-closing behaviour.
    • Fixed cross-window drag-and-drop and tab moves initiated by extensions or context menus.
    • Prevented selected tabs from remaining hidden inside collapsed trees.
    • Refreshed expand and collapse controls with RTL and reduced-motion support.
  • Fixed Chase website compatibility when Waterfox's built-in content blocker is enabled.
  • Fixed selected Waterfox colour palettes sometimes being overwritten by a later default-theme update.
Known Issues
  • Privileged extensions may not be fully supported.
  • Trying to open a link in a new private tab via the context menu opens said link in a normal tab.
View originalPermalink
How 6.7.0-beta.2 went

6.6.16.1

Changed 1
  • Change default search engine to Qwant in 26 regions including most of Europe, Australia, Canada, Japan, Korea, Singapore, the UK, and the US
Fixed 3
  • Correct Qwant being selected as the default in unsupported regions
  • Force Qwant AI answers/summaries to disabled by default
  • Fix unsupported locale-country query values such as es_US which would result in Qwant refusing to return results
Security 1
  • Include all security fixes that have landed to date for Firefox ESR 140.13

[!IMPORTANT] Waterfox 6.6.16.1 is a hotfix for the search rollout:

  • Corrects Qwant being selected as the default in unsupported regions.
  • Attempts to force Qwant AI answers/summaries to disabled by default.
  • Fixes unsupported locale-country query values such as es_US, which would result in Qwant refusing to return results.
Security

Waterfox 6.6.16 includes all security fixes that have landed to date for the upcoming Firefox ESR 140.13, which Mozilla is due to release on 21 July. Rather than hold these back for two weeks, we're shipping them now alongside the search change below.

The corresponding Mozilla Foundation Security Advisory will be published when ESR 140.13 is released. If any further security fixes land upstream before then, they will follow in a point release.

Search
Qwant is the new default

Back in 6.6.13 we set 1.org as a temporary default while we worked out a longer term arrangement. That arrangement is now in place - Waterfox has partnered with Qwant, the independent, privacy-focused search engine based in Paris, and it is now the default search engine on all platforms.

You can read the full story behind the partnership, and why it matters for Waterfox's independence, in the announcement post.

  • Qwant is the default in 26 regions: most of Europe, plus Australia, Canada, Japan, Korea, Singapore, the UK, and the US.
  • Everywhere else, DuckDuckGo is the default until Qwant supports your region.
  • As always, if you've ever set your own search engine, that choice stays put - the new default only applies if you were on the previous default or are installing fresh. You can switch any time in Settings.

[!NOTE] When Qwant becomes available in more regions, the default in those regions will switch from DuckDuckGo to Qwant. As above, that only applies if you've left the default alone - if you've manually selected DuckDuckGo yourself, your choice stays put.

Ad blocker allowance follows the default

As explained in 6.6.13, the built-in ad blocker allows search ads only on Waterfox's default search provider - that allowance follows whichever provider we ship as the default, so it now applies to Qwant. Those ads are how the partnership funds Waterfox, and you can turn the allowance off in the blocker settings if you prefer.

[!TIP] Allowing ads on Qwant search pages is the single most effective way to support Waterfox at no cost. If you use a third-party ad blocker instead of the built-in one, please consider allowlisting Qwant.

6.7 Beta

As promised in 6.6.15, the first beta of the next major version is here: Waterfox 6.7.0-beta.1 is ready for testing. It moves Waterfox to the ESR 153 platform and brings tree tabs natively into vertical tabs, a new Nova style and colour system, ad blocker improvements, and a reworked first-run setup.

If you'd like to help test the next big update before it reaches the stable channel, give it a try and file bug reports for anything you hit.

View originalPermalink
How 6.6.16.1 went

6.7.0-beta.1

Pre-release
Added 6
  • Tree tabs are now a native part of the browser built directly into the vertical tab strip, with settings for new tab attachment, parent closure behavior, double-click behavior, branch auto-collapse, mute propagation, and nesting depth
  • Nova is a new browser style option alongside Proton and Photon, with a sharper appearance and brighter active tab line
  • Twelve color palettes replace the old three-option accent color setting, with light and dark variants that follow system theme and apply to built-in pages
  • Qwant joins the search partner list with ads allowed on qwant.com by default
  • Firefox profile migrator installs companion app manifests for password managers and similar tools on macOS and Linux
  • Translation models download on demand so page translation is no longer limited to bundled language pairs
Changed 10
  • Move from Gecko ESR 140 to Gecko ESR 153, bringing upstream engine, performance, and security work
  • Ad Blocking moves to its own pane in Settings out of Privacy and Security
  • Anti-adblock and annoyance scriptlets now inject before page scripts run to fix sites that raced the blocker
  • Redirect resources grow from 17 to 62 to reduce page breakage from blocked requests
  • Exceptions added in private windows last only until the session ends and are kept separate from normal exceptions
  • Ad blocking now verifies blocked page origin, caps list download sizes, refuses redirects, and performs atomic cache writes
Removed 2
  • Onboarding screens recommending extensions and showing Android QR code are removed
  • Tree tabs no longer support the full set of keyboard commands, custom CSS editor, and extension API from the previous extension

Waterfox 6.7 moves from Gecko ESR 140 to Gecko ESR 153. This brings a year of upstream engine, performance, and security work into one release. Much of the Waterfox layer is also rebuilt to run natively inside the new platform.

[!IMPORTANT] This is a beta - everything below is ready to test, and bug reports are helpful.

Tree Tabs

Waterfox 6.6 shipped tree-style tabs as a bundled extension, a fork of Tree Style Tab, living in its own sidebar panel. In 6.7, tree tabs are a native part of the browser, built directly into the vertical tab strip.

  • Tree tabs share code with vertical tabs, tab groups, the sidebar customisation panel, and themes, so all four stay in sync.
  • Tree structure now saves through the browser's own session store; existing trees and settings migrate on upgrade.
  • How far you drag a tab horizontally sets its nesting depth, and a tab's whole subtree moves with it, including across windows.
  • Settings under Tabs and Browsing covers how new tabs attach, what happens when you close a parent, double-click behaviour, branch auto-collapse, mute propagation, and nesting depth.

[!WARNING] The native implementation is leaner than the old extension. It requires vertical tabs (the old sidebar could sit next to a horizontal tab bar), and several extras have not carried over: the large set of keyboard commands, the custom CSS editor, and the API other extensions could hook into. File a bug report if you relied on one of these.

Nova and Colour System

The browser style is now a choice of three: Nova, a new, sharper Waterfox style with a brighter active tab line; Proton, modern stock styling; and Photon, the classic Waterfox look with the Lepton chrome refinements. New installs start on Nova. If you are upgrading, a one-time dialog lets you keep your current style or switch to Nova; nothing changes until you choose.

The old accent colour setting, which had three options, is replaced by twelve palettes, from Smoke and Ash through Sun, Spark, Flame, Lavender, Lagoon, and Pine, each with light and dark variants that can follow your system theme. The palette also applies to built-in pages, so Settings and other internal pages use your chosen colours.

The Look and Feel pane's long list of small tweaks (corner rounding, icon hiding, centring, and similar) is no longer in Settings. Seven remain for Photon: transparency, auto-hide options, close button on hover, and drag space. The rest still work for Photon via about:config. File a bug report for any toggle you rely on.

Ad Blocking

The built-in blocker, shipped since 6.6, changes in several ways:

  • Moves to its own Ad Blocking pane in Settings, out of Privacy and Security.
  • Anti-adblock and annoyance scriptlets now inject before page scripts run, fixing sites that previously raced the blocker and won.
  • Redirect resources, the blank media and neutered scripts used as stand-ins for blocked requests, grow from 17 to 62, so fewer blocked requests break the page.
  • Exceptions added in a private window last until the session ends and are kept separate from your normal exceptions; permanent exceptions no longer apply in private browsing.
  • The "Load anyway" button now verifies the request came from a blocked page, list downloads are capped in size and refuse redirects, and cache writes are atomic.

[!TIP] Qwant has joined the search partner list, so the blocker allows ads on qwant.com by default, the same funding arrangement used for our other search partners. Turn it off in the Ad Blocking pane if you prefer.

Search Defaults

The engine line-up is unchanged (1.org, Bing, DuckDuckGo, Ecosia, Google, Mojeek, Qwant, and Waterfox Private Search). The default changes from 1.org everywhere to Qwant in 26 regions (most of Europe, plus Australia, Canada, Japan, Korea, Singapore, the UK, and the US), and DuckDuckGo everywhere else.

[!NOTE] When Qwant becomes available in more regions, the default in those regions will switch from DuckDuckGo to Qwant. As above, that only applies if you've left the default alone - if you've manually selected DuckDuckGo yourself, your choice stays put.

Onboarding Setup and Firefox Import

Onboarding setup is rebuilt and covers browser style and density, theme colour, tab arrangement (horizontal, vertical, or tree) and tab strip placement, privacy defaults, and data import. It is now localised; earlier versions were English-only. The old screens recommending extensions and showing an Android QR code are gone.

The Firefox profile migrator is rewritten and brings over bookmarks, history, form data, cookies, and passwords. Extensions using native messaging now also find companion app manifests installed for Firefox on macOS and Linux, so password manager connectors and similar tools work without reinstalling anything.

Existing users keep their current setup: the only prompt after upgrading is a short dialog offering to keep Photon or switch to Nova.

Security & Privacy
  • Certificate revocation data (OneCRL and CRLite) and the add-on blocklist update over the network again. 6.6 froze these at build time along with everything else; 6.7 syncs only the collections that matter for security and keeps the rest on offline bundles.
  • Translation models now download on demand, so page translation is no longer limited to the language pairs bundled at build time.
  • 6.6 partially neutered Safe Browsing; 6.7 disables it fully, so no Google Safe Browsing endpoints are contacted.
  • The AI surfaces that came with the Firefox 153 platform (chat sidebar, shortcuts, and related controls) are off by default.
  • The address bar trust panel is included; the lookups that would query external breach data are disabled.

Ultra Protection, our DNS over Oblivious HTTP setup, stops the DNS provider from linking requests back to you. It now has Settings controls with a fallback policy choice, and the relay has been Waterfox's default DNS transport since 6.6.

Settings

6.7 adopts the redesigned Settings. Appearance controls, including the status bar toggles, move under Appearance; tab bar and bookmarks toolbar position plus the tab context menu extras move under Tabs and Browsing; ad blocking gets its own pane; and settings that exist only in Waterfox carry a "Waterfox Exclusive" badge. New tab URL is now configurable, and automatic tab grouping has Settings controls for the toggle and placement.

A few controls from 6.6 lose their UI: the WebRTC peer connection toggle, the referrer header policy menu, and the load images and enable JavaScript checkboxes. The preferences still work via about:config.

Removed in 6.7

Installing extensions directly from the Chrome Web Store and Opera Addons no longer works; the compatibility shim that converted those packages did not survive the platform jump. In truth, this was only ever technically supported - the shim could install a .crx package, but Chrome and Firefox WebExtensions have diverged so far that actually bridging the gap is a huge effort, and I'd be surprised if many easily accessible Chrome extensions still worked in practice. File a bug report if you rely on this.

Other Changes
  • ARM64 builds are now available for Windows, macOS, and Linux, including the Debian and RPM packages.
  • Zoom controls now sit on the status bar by default, and when Nova is in use the status bar becomes a floating pill, matching the rest of the Nova chrome.
  • The New Tab page shows the search box by default.
  • Automatic tab grouping now defaults to off (it was on in 6.6); turn it on under Tabs and Browsing.
  • Bundled emoji font updated to Twemoji 17.0.2.

Found anything else? File a bug report.


Full release notes with screenshots and the palette showcase: waterfox.com/releases/6.7.0-beta-1

View originalPermalink
How 6.7.0-beta.1 went

6.6.16

Changed 3
  • Set Qwant as the default search engine in 26 regions including most of Europe, Australia, Canada, Japan, Korea, Singapore, the UK, and the US
  • Use DuckDuckGo as the default search engine in regions where Qwant is not yet supported
  • Apply the ad blocker allowance for search ads to Qwant as the new default search provider
Security 1
  • Include all security fixes that have landed to date for Firefox ESR 140.13
Security

Waterfox 6.6.16 includes all security fixes that have landed to date for the upcoming Firefox ESR 140.13, which Mozilla is due to release on 21 July. Rather than hold these back for two weeks, we're shipping them now alongside the search change below.

The corresponding Mozilla Foundation Security Advisory will be published when ESR 140.13 is released. If any further security fixes land upstream before then, they will follow in a point release.

Search
Qwant is the new default

Back in 6.6.13 we set 1.org as a temporary default while we worked out a longer term arrangement. That arrangement is now in place - Waterfox has partnered with Qwant, the independent, privacy-focused search engine based in Paris, and it is now the default search engine on all platforms.

You can read the full story behind the partnership, and why it matters for Waterfox's independence, in the announcement post.

  • Qwant is the default in 26 regions: most of Europe, plus Australia, Canada, Japan, Korea, Singapore, the UK, and the US.
  • Everywhere else, DuckDuckGo is the default until Qwant supports your region.
  • As always, if you've ever set your own search engine, that choice stays put - the new default only applies if you were on the previous default or are installing fresh. You can switch any time in Settings.
Ad blocker allowance follows the default

As explained in 6.6.13, the built-in ad blocker allows search ads only on Waterfox's default search provider - that allowance follows whichever provider we ship as the default, so it now applies to Qwant. Those ads are how the partnership funds Waterfox, and you can turn the allowance off in the blocker settings if you prefer.

[!TIP] Allowing ads on Qwant search pages is the single most effective way to support Waterfox at no cost. If you use a third-party ad blocker instead of the built-in one, please consider allowlisting Qwant.

6.7 Beta

As promised in 6.6.15, the first beta of the next major version is here: Waterfox 6.7.0-beta.1 is ready for testing. It moves Waterfox to the ESR 153 platform and brings tree tabs natively into vertical tabs, a new Nova style and colour system, ad blocker improvements, and a reworked first-run setup.

If you'd like to help test the next big update before it reaches the stable channel, give it a try and file bug reports for anything you hit.

View originalPermalink
How 6.6.16 went

6.6.15

Security 1
  • Fix remaining relevant issues from Mozilla Foundation Security Advisory 2026-58 to bring the 6.6 series fully in line with the advisory
Security

Waterfox 6.6.15 is a follow-up security release for Mozilla Foundation Security Advisory 2026-58.

The majority of fixes related to this advisory were already included in Waterfox 6.6.14. This release fixes up the remaining relevant issues and brings the 6.6 series fully in line with the advisory.

Coming Soon

A beta release for the next major version of Waterfox, 6.7, based on Gecko 153, will be available soon. Keep an eye out if you would like to help test the next big update before it reaches the stable channel.

View originalPermalink
How 6.6.15 went

6.6.14

Added 1
  • Added a new Always store cookies/data for this site toggle to the site information panel
Changed 4
  • Adjusted how Waterfox presents itself to websites to improve compatibility with Chase and Discord
  • Improved reliability of handling modern filter lists in the built-in ad blocker
  • Reduced likelihood of pages briefly showing ads or annoyances before the ad blocker catches up after opening Waterfox
  • Reduced background work performed by the ad blocker when a page starts loading
Fixed 2
  • Worked around a bug introduced in macOS 26.5 that could cause Waterfox and other Gecko-based browsers to crash
  • Fixed ad blocker to correctly pick up site-specific ad-blocking fixes instead of ignoring or misreading them
Web Compatibility

Attempted compatibility improvements for Chase and Discord by adjusting how Waterfox presents itself to the site.

These changes are compatibility workarounds rather than fixes for a technical limitation in Waterfox. Some sites appear to rely on user agent checks to decide whether a browser is supported, so Waterfox now makes a better effort to identify itself in a way those checks will accept. There is no guarantee these fixes will work, but I have not found a technical reason why these websites would not work that hasn't already been implemented in Waterfox.

macOS
  • Worked around a bug introduced in macOS 26.5 that could cause Waterfox, as well as any Gecko based browser, to crash.
Site Data
  • Added a new Always store cookies/data for this site toggle to the site information panel. This gives you a quick way to let a trusted site keep its cookies and site data, which can help when a site keeps forgetting logins, preferences, or other saved state because of stricter cookie settings. Thanks to Defelo for the PR, and to LibreWolf for developing the original patch.
Ad Blocker

The built-in blocker has received another round of reliability and performance improvements:

  • Modern filter lists should now be handled more reliably.
  • Some site specific ad-blocking fixes should now be picked up correctly instead of being ignored or misread.
  • Pages loaded immediately after opening Waterfox should be less likely to briefly show ads or annoyances before the blocker catches up.
  • The blocker now does a little less background work when a page starts loading.

This will hopefully enable greater compatibility with websites like YouTube, working around their anti-adblock messages.

View originalPermalink
How 6.6.14 went

6.6.13

Changed 5
  • Internationalised domain names are now handled and displayed by the browser as unicode, instead of always being shown as punycode
  • Dithering is now enabled for CSS rendering, which should eliminate visible colour banding on gradients
  • Attempted compatibility improvements with sites such as LinkedIn that were not rendering correctly
  • Built-in ad blocker is now enabled by default
  • Default search engine changed to 1.org
Fixed 1
  • Fixed an issue where tracking protection wasn't blocking things properly because the required assets weren't being bundled with the browser
Removed 1
  • Startpage removed as a search provider
Bug Fixes
  • Tracking protection assets: Fixed an issue where tracking protection wasn't blocking things properly because the required assets weren't being bundled with the browser.
Web Compatibility
  • IDN unicode display: Internationalised domain names are now handled and displayed by the browser as unicode, instead of always being shown as punycode. This provides better legibility for users who visit websites with non-latin characters.
  • CSS dithering: Dithering is now enabled for CSS rendering, which should eliminate visible colour banding on gradients.
  • LinkedIn and others: Attempted compatibility improvements with sites such as LinkedIn that were not rendering correctly.
Ad Blocker

The built-in ad blocker is now enabled by default! After several rounds of preview testing across 6.6.11 and 6.6.12, the blocker is ready for general use - giving you high performance ad blocking out of the box while supporting Waterfox at the same time.

[!TIP] If you are already using another ad blocker, don't worry - it will continue to work instead of the built-in one. But please consider giving the built-in blocker a try, as it's a great way to support Waterfox.

You can follow the feedback issue at Native Ad Blocker - Feedback · Issue #4182.

Search
Startpage removed as a search provider

We've been asked to remove Startpage as our default search provider, and from the browser options completely. This is out of our control, but we wanted to be transparent about the change rather than having it appear without explanation.

New temporary default: 1.org

The default search engine is for the time being, 1.org, a charitable search engine. Profits are shared with a charity of your choice once you sign up, or otherwise go to the spotlight charity of the month. We think it's a great fit while we work out a longer term arrangement.

[!Note] If you'd like to support Waterfox and don't want to use the built-in ad blocker, please consider disabling your ad blocker on our default search provider. The default may change as we work out longer term partnerships.

If you'd rather avoid ads in search entirely, please consider switching to a different provider (such as Waterfox Private Search below) rather than blocking ads on our default - blocked traffic is worth less to search providers, which reduces the revenue share that helps fund Waterfox.

Waterfox Private Search

Waterfox Private Search is now only $5/month for unmetered searches (within reason). It's a completely ad free experience, with customisation options and an independent European web index powering it - a great option if you'd like to avoid big tech entirely.

Long term search partner

We are currently in conversations with one of the larger search providers to bring back the search experience users have come to expect. As a small project these discussions move slowly, but we wanted you to know it's actively being worked on.

View originalPermalink
How 6.6.13 went

6.6.12

Added 6
  • Added Custom Filter Lists manager dialog to add and remove custom filter list URLs from the UI
  • Added search box to Filter Lists screen to quickly find lists
  • Added Refresh now button for manual filter list updates
  • Added refresh interval dropdown with options 4h, 8h, 12h, 24h, 7d, or default
  • Added per list last updated and next refresh information display
  • Added source link icon for each filter list
Changed 6
  • Changed filter list update logic to respect each list's own Expires value instead of a fixed 12h interval
  • Improved cosmetic CSS injection to only run on HTML pages, avoiding breakage on XML or text content
  • Improved cosmetic filtering with hard cap on queried DOM elements to prevent runaway processing
  • Changed cosmetic filtering to use CSS rule insertion instead of rebuilding the full style text
  • Improved ad blocker extension detection to identify conflicting extensions only by known extension IDs, removing pattern matching on name and description
  • Optimized network observers to register and unregister based on ad blocker state
Fixed 2
  • Improved error handling when loading the ad blocker engine cache
  • Improved input sanitization before data is passed to the ad blocker engine
Security 1
  • Fixed multiple security vulnerabilities as described in Mozilla Foundation Security Advisory 2026-32
Security
Ad Blocker (preview)

The built-in ad blocker introduced in 6.6.11 has received a few improvements in this release. It remains in preview testing - you can follow the feedback issue at Native Ad Blocker - Feedback · Issue #4182.

Custom Filter Lists manager

A new dialog lets you add and remove your own filter list URLs directly from the UI, rather than being limited to the built-in lists. A new button has been added to the blocker preferences to open the manager.

Filter Lists screen improvements

The existing Filter Lists screen has received major updates:

  • Search box to quickly find lists
  • "Refresh now" button for manual updates
  • Refresh interval dropdown (4h, 8h, 12h, 24h, 7d, or default)
  • Per list "last updated / next refresh" information
  • Source link icon for each list
Less wasteful update logic
  • Each list's own Expires value is now respected, instead of a fixed 12h interval applied to all lists
  • Configurable refresh interval
  • Manual refresh method exposed to the UI
  • Better error handling when loading the engine cache
  • Safer input sanitization before data is passed to the engine
  • Network observers are registered and unregistered based on blocker state
Better cosmetic filtering
  • Early check for whether the blocker is enabled
  • Cosmetic CSS injection now only runs on HTML pages, avoiding breakage on XML or text content
  • Hard cap on queried DOM elements to prevent runaway processing
  • Uses CSS rule insertion instead of rebuilding the full style text
Stricter extension detection

Conflicting ad blocker extensions are now identified only by known extension IDs. Pattern matching on extension name and description has been removed, reducing false positives from unrelated extensions.

View originalPermalink
How 6.6.12 went
View all

Discussion