-Fixed add-on/GMP update calls to Mozilla services. -Enabled accessibility features. -Enabled parental Controls features (Windows only). -Changed blocklist hosting to self-hosted. -Removed leveraging the blocklist for CRL purposes. -Included the Universal Runtime Libraries with the browser. -No longer enforcing the "preferred" cipher suite profile on Http/2. -Added support for the worker-src CSP directive. -Fixed freetype glyph metrics in Skia (fixes Freetype 2.8.1+ issues). -Fixed an issue with ContentSecurityManager not passing the correct context. -Fixed a number of issues with Contenteditable elements. -Fixed a number of issues with pointer events. -Implemented "cookie-averse document objects" to mitigate cookie injection. -Fixed an issue with SVG text-based image masks. -Fixed the installer checking for Firefox instead of Basilisk. -Enabled the use of 64-bit plug-ins other than Flash and Silverlight. -Made the SVG texture cache more lenient to large-resolution SVG images. -Fixed several crashes and memory safety hazards. -Fixed several security bugs: CVE-2017-7837, CVE-2017-7832, CVE-2017-7830, CVE-2017-7835, CVE-2017-7831, CVE-2017-7838, CVE-2017-7839, CVE-2017-7828, CVE-2017-7840, and several others from Firefox 57 that do not have a CVE designation. |