Waterfox: Popular Firefox Fork But Never Discussed Here?

Security issues of Firefox:

lack of site isolation (Project Fission - MozillaWiki)
CFI, (510629 - (cfi) [meta] Ship Control Flow Integrity (CFI))
ACG (1381050 - [meta] Deploy Arbitrary Code Guard (ACG) on Windows)
CIG (1378417 - [meta] Support Binary Signature Policy and eventually Code Integrity Guard on Windows)
win32k lockdown (Bug List: win32k)
lack of Linux/macOS gpu isolation (https://wiki.mozilla.org/Security/Sandbox/Process_model#GPU_Process) ???
lack of a hardened malloc (PartitionAlloc Design)
complete lack of any sandboxing whatsoever on Android (1565196 - (android:isolatedProcess) [meta] Enable android:isolatedProcess on GeckoView)

Most of these issues are decade old which is really concerning.

2 Likes