LibreWolf (Firefox-Based Browser)

I appreciate your reply!

I wasn’t talking about the current day but in 6 months and beyond.

EDIT:
Nevermind… Firefox is definitely struggling.

Just wanted to share that I’ve been looking for a similarly easy to use alternative to Brave’s forgetful browsing feature. If you click the lock button by the search bar on LibreWolf, it gives you the option to always store cookies/site data for specific websites, while by default, website cookies will be cleared on exit. Very nice.

The slow on updates thing is apparently outdated.

Librewolf update regularly within 1-3 days.

There was another concern about auto-updates which have also been resolved now. When you install it, you have the option to install a helper file that takes care of the update automatically.

There isn’t much against Librewolf left. You can always try it, and if you encounter lots of website breakage or don’t like it, then switch to another browser.

No because the strong privacy will still aplly to all other sites, especially does in different containers.

Librewolf is advanced privacy.
Extreme privacy would be Tor inside Whonix who itself is inside QubesOS or Secure Blue

After reviewing the arguments against LibreWolf in the discussion and spending many hours in research, I have come to the conclusion that LibreWolf should be included in the browser recommendations. In the following, I will address the objections that have been raised against LibreWolf and explain why they don’t apply in my opinion.

This are the objections I will address:

  • LibreWolf receives security fixes slower than FireFox.
  • LibreWolf doesn’t offer anything that FireFox can’t do.
  • LibreWolf doesn’t offer anything that MullvadBrowser can’t do / MullvadBrowser is LibreWolf, just better.
  • LibreWolf doesn’t have automatic updates.
  • LibreWolf has no use case, in either way you wouldn’t use LibreWolf.

LibreWolf receives security fixes slower than FireFox.

This is the most commonly used and according to those who don’t want LibreWolf in the PG recommendations, probably the best:

So I did some research and found out that if we take the last twenty security fix delays, we get an average security fix delay of 1.7 days. Here’s the whole Comparison of Firefox and LibreWolf Release Dates:

LibreWolf vs FireFox Release QUickness.txt (2.4 KB)

And because I was really very interested, how much the security fix delay of other, on Privacy Guides recommended forks is, I did the same research with the MullvadBrowser, which is the first recommended Browser on the Privacy Guides Browser Recommendations. It had an average security fix delay of 1.3 days. Here’s the whole Comparison of Firefox and MullvadBrowser Release Dates:

MullvadBrowser vs FireFox Release QUickness.txt (3.2 KB)

If 1.3 days of security fix delay is not so relevant that a browser is not included in the Privacy Guides recommendations, then it would probably be ridiculous to argue that 1.7 days would be too much to be included in the Privacy Guides browser recommendations.

LibreWolf doesn’t offer anything that Firefox can’t do.

That’s not correct. First, the most frequently mentioned and probably also most important point: you don’t have to configure and maintain (= checking each time whether ArkenFox has been updated and maybe updating it. You have to do that, otherwise there’s a risk that protection against a possible existing new tracking techniques isn‘t activated) FireFox with ArkenFox. Second, there’s an extra category under the settings that gives GUI access to settings that are only accessible in Firefox through about:config. Third, it’s significantly easier in LibreWolf to set/remove exceptions for cookie and website data deletion on close. You simply click on the lock in the URL bar and activate/deactivate the toggle “LibreWolf: Always store cookies/data for this site”. This toggle doesn’t exist in Firefox with “Delete cookies and site data when Firefox is closed” turned on (or off). Instead, you have to:

  1. Option: Lock in the URL bar ➝ “Connection secure” ➝ “More information” ➝ “Permissions” ➝ Deactivate “Set Cookies Use Default” ➝ “Allow”

  2. Option: Menu ➝ “Settings” ➝ “Privacy & Security” ➝ Scroll to “Cookies and Site Data” ➝ “Manage exceptions” ➝ Enter/paste URL ➝ Click Enter ➝ “Save Changes”.

LibreWolf doesn’t offer anything that MullvadBrowser can’t do / MullvadBrowser is LibreWolf, just better.

That’s not true. You can use MullvadBrowser for Browsing if you don’t want to log in into sites. But if you want to log in into websites,… you can’t. There’s an issue that’s present for two years, were disabling “Always use private browsing mode“ and adding a website to the whitelist doesn’t keep cookies and websitedata reliable. And since the 1.7 day security fix update delay doesn’t seem so relevant not to include it in the Privacy Guides Recommendations (see above), and LibreWolf is much more user-friendly (because of the mentioned three reasons, see above) than FireFox and ArkenFox, LibreWolf should be included in the Privacy Guides Browser Recommendations.

Privacy Guides should recommend LibreWolf at very least until the above mentioned issue is fixed (I would argue that it should still be recommended afterwards).

LibreWolf doesn’t have automatic updates.

This argument is out of date, it has now automatic updates for all supported platforms.

LibreWolf has no use case, in either way you wouldn’t use LibreWolf.

This objection was actually refuted by the refutation of the 2nd and 3rd arguments.

Great analysis and research! Couldn’t agree more!

I would also add that Librewolf saves time and is much easier to recommend to non-privacy folks.

Wanna know something funny?

Firefox 145 released on November 11, 2025. This release has security fixes for 9 High CVEs.

LibreWolf bumped the Firefox version to 145 on November 12, 2025. But guess what, their build has been failing since then and users have been using an outdated Firefox version for 5 days now and there have not been any commits to the repo trying to fix it.

This is nonsense. There is no crowd for arkenfox. arkenfox is a template with sensible defaults anyway, you are supposed to change things to your liking if you want. What you are talking about would only impact Tor/Mullvad browser.

See my post from here, this is being worked on.

Seems to be the same with MullvadBrowser. If you look at the official MullvadBrowser Releases Page, the last Release is 15.0, released on 29. Oct., so before the

and Privacy Guides recommends MullvadBrowser.

So you could just ignore every ArkenFox-UpDate or what do you mean by that?

See my reply to that here:

Good catch. No idea why the releases are not being made considering Mullvad Browser 15.0.1 has been finished. I opened an issue on github. @ruihildt

Edit: It is tagged but no proper release has been made and no downstream packagers have updated.

I didn’t say that. If you are late to update, you aren’t going to immediately stick out since you are already unique. Yes, you should update, but it isn’t going to make a huge difference since the changes arkenfox makes in each version are getting smaller over time anyway.

Until LibreWolf manages to have consistent updates, it shouldn’t be recommended; until then, Persistent mode is probably already released anyway, making the recommendation even more useless.

It does have consistent updates though.

Did you not read my other post? It still hasn’t been updated to release 145.

Yes, but are you suggesting Mullvad Browser shouldn’t be recommended either?

No? Mullvad Browser already has been updated and has a working build. For some reason there hasn’t been made a release yet.

LibreWolf has no working build for 145 and currently nothing has been done to make one.

Neither does Mullvadbrowser! And really, 5 days is worrying, but the MullvadBrowser had this issue in the past already: If you look at my table, you see that the security vulnerabities fixed in FireFox 139.0, among others one „critical“-security fix (which is even much higher than a „high“-security fix) and seven „moderate“-security fixes, were fixed in MullvadBrowser six days after firefox!

I still don’t understand why you keep trying to justify LibreWolf being five days behind on updates by pointing to Mullvad Browser’s six-day gap.

LibreWolf should be recommended as a Firefox + arkenfox replacement, not a Mullvad Browser alternative.

I’m not saying Mullvad being behind is good — I’m saying that for LibreWolf to be recommended as a Firefox + arkenfox replacement, it must add value compared to that setup, and being behind on updates does not add value, especially as it’s often recommended to less technically knowledgeable users who would rely more on faster security fixes not less.

Because of the fact that MullvadBrowser is recommended and LibreWolf isn‘t! When you say, LibreWolf shouldn‘t be added to the browser recommendations because of a five day security fix delay, you should consequently also say, that MullvadBrowser shouldn‘t be recommended because it had also such a delay! But that‘s not the case:

EDIT: And I am not saying this only because of the missing 15.0.1/15.1 Release, but also because of the 6day security fix delay which happened in the past I already mentioned above

Mullvad Browser is almost always worse in terms of security than regular Firefox because it uses the ESR version and relies on CVE backports from the normal releases, which has its own problems.

Mullvad Browser adds immense value compared to what you can achieve with normal Firefox; that’s why it is recommended. It isn’t recommended for being the most secure.

LibreWolf would have to add value compared to Firefox + arkenfox to be considered, but being behind on updates does not add value. You can have the fastest updates and privacy benefits by sticking with Firefox + arkenfox without relying on a third party for updates.

If LibreWolf had a longer track record of pushing updates quickly—which it almost had until now—then maybe it could be up for discussion, but considering its history in the past few years I doubt it.