​Firefox 58 arrives with tracker blocking to make browsing faster, and fixes for dozens of security flaws

Firefox 57 had a critical flaw that could be triggered when the browser makes a WebRTC connection using "touch tone" signals common in old landline handsets.
Written by Liam Tung, Contributing Writer

Video: New Firefox 58 gets speed boost

Firefox 58 gives you faster performance, but you'll want to update anyway to fix a handful of critical flaws.

The latest version of the Firefox browser builds on the recent overhaul known as Firefox Quantum, version 57 of Mozilla's browser. Last week, Firefox developers flagged speed improvements from the new WebAssembly and compiler improvements in Firefox 58.

Mozilla has also improved the way Firefox renders graphics -- launching an improved engine that more efficiently paints your screen, using a dedicated CPU thread -- and caches JavaScript to help pages load faster. Meanwhile, Firefox on Android gains new support adding Progressive Web Apps to the home screen to use like native apps.

Mozilla is also promoting a refreshed Tracking Protection feature. It arrived two years ago in Private Mode but Firefox 57 allowed users to enable the privacy feature at all times. Mozilla says tests show that enabling it all the time actually speeds up page loads. It's also available on Firefox for iOS and Android.

Given the relative decline of PCs, Firefox's future still depends heavily on increased adoption on mobile platforms. Mozilla has tweaked Firefox on Android's bookmarking feature to make it easier to view, organize, and create new folders, and move bookmarks into different folders.

For Progressive Web Apps (PWA), Firefox on Android now displays a house-shaped button in the address bar when users visit a site that is PWA. Adding the app to the home screen can be done by tapping the house button. Mozilla has posted a short demo on YouTube of the 'Add to Home Screen' feature on YouTube. The homescreen icons have a small Firefox badge in the bottom right corner. Once opened, each PWA opens as a separate entry in the app switcher.

And, following on from Mozilla's Firefox recent fixes for two variants of the widespread Meltdown and Spectre flaws, Firefox 58 addressed a further 32 vulnerabilities, consisting of four critical, 13 high, 13 moderate, and three low severity bugs.

Download now: Encryption policy (free PDF)

One of the critical bugs can surface during a WebRTC connection to systems that use DTMF or Dual-Tone Multi-Frequency signals. DTMF signals were used in 'touch tone' phones to have different tones represent buttons on a keypad. In the context of WebRTC, computers can use DTMF when sending a command to a teleconferencing system. The bug results in a potentially exploitable crash.

Mozilla developers also found a group of memory safety bugs in Firefox 57 that appeared to be a memory corruption issue that could, with some effort, be exploit to run arbitrary code.

The Firefox ESR 52.6 release contains fixes for 11 of the bugs fixed in Firefox 58, including the critical WebRTC flaw and critical memory safety bugs.


Mozilla: Firefox 57 is so fast we're calling it Firefox Quantum

Firefox Quantum will test whether Mozilla's efforts to modernize its browser can pay off.

Why is Firefox Quantum so fast? Mozilla reveals a tweak that turbo-charged its browser

Mozilla's latest version of its Firefox web browser gets a performance boost from a privacy feature.

Firefox Quantum: 170 million installs so far, as more Chrome users jump ship

Firefox sees a bump in installs from Chrome users after the big Quantum overhaul.

3 awesome features coming to Firefox that you can get right now (CNET)

The upcoming Firefox 59 will help you stop sites from asking for permission to send you notifications and know your location, but you can stop these right now in the current build of Firefox with a little digging.

How to manage Firefox Quantum site permissions (TechRepublic)

Jack Wallen walks you through the process of managing both default and site permissions with Firefox Quantum, so you can enjoy a more secure and reliable browsing experience.

Editorial standards