Mozilla ships Firefox 8, patches 8 bugs and adds Twitter search
Automatically disables add-ons installed behind users' backs
By Gregg Keizer | Computerworld US | Published: 13:30, 10 November 2011
Mozilla on Tuesday released Firefox 8, adding Twitter search to the browser and patching eight vulnerabilities.
Since Mozilla kicked off its every-six-week upgrade cycle last summer, each new Firefox has had relatively few visible changes. That held true yesterday.
Firefox 8's most notable addition was Twitter as a choice in Firefox's search bar, letting users look up topics, hashtags and usernames on the micro-blogging service. Twitter search is currently available only in the English, Japanese, Portuguese and Slovenian editions of Firefox.
Related Articles on Techworld
Mozilla also made good on a promise last August to automatically disable add-ons installed without user approval. Behind-the-back add-ons have cropped up at times, most recently in January when one bundled with Skype caused so many browser crashes that Mozilla blacklisted it. When users start Firefox 8, all add-ons that have been surreptitiously installed are turned off by default.
Other changes and enhancements to Firefox 8 included on-demand tab loading at startup for faster restored sessions, and developer support for additional features of the hardware-accelerated 3D graphics standard, WebGL.
As part of Tuesday's upgrade, Mozilla also fixed eight vulnerabilities, five of them rated "critical," the most-serious ranking in Mozilla's threat scoring system. The remaining three bugs were labeled "high," the next-most-serious rating.
One of the patches was for a data theft bug originally fixed in August when Mozilla launched Firefox 6, but which was reintroduced in Firefox 7 after developers launched a new Windows graphics acceleration framework, dubbed "Azure," in the September upgrade.
Mozilla blamed a Mac-only vulnerability on Apple and Intel, saying that the flaw could let attackers sniff out secrets by monitoring a Mac's graphics processor.
"This problem is due to a bug in the driver for Intel integrated GPUs [graphics processing units] on recent Mac OS X hardware," said Mozilla in the accompanying advisory .
Mozilla yesterday also released Firefox 3.6.24, a security update that patched three vulnerabilities. The aging edition - Mozilla shipped Firefox 3.6 in January 2010 - is still supported, in large part because enterprise users have resisted the company's rapid release tempo.
But the end is in sight for Firefox 3.6, as Mozilla has now rescheduled an upgrade offer originally slated for last month that was canceled at the last minute. The pitch, which will urge users to upgrade to Firefox 8, will now appear 17 November.
According to plans previously outlined by Mozilla, the company intends to stop patching Firefox 3.6 three months after it offers users the upgrade opportunity.
As of last month, Firefox 3.6 was still the preferred browser of approximately one-fourth of all Mozilla users.
Windows, Mac and Linux editions of Firefox 8 can be downloaded manually from Mozilla's site, while people running Firefox 4 or later will be offered the upgrade through the browser's own update mechanism.
The next version of Firefox is currently scheduled for release 20 December.