51.rc - August 27, 2026 ======================= * Bugs fixed: - #2898 Invalid bookmark import crashes browser (Fernando Muñoz) - #2903 XSS/HTML injection in error page (Michael Catanzaro) - #2921 (CVE-2026-77682) Autofill JS Code Injection via CSS Selector (Michael Catanzaro) - #2922 (CVE-2026-77679) WebExtension XPI Path Traversal ZIPSLIP (Fernando Muñoz) - #2928 Link clicked in another app opens in the fullscreen window during fullscreen video (Semen Fomchenkov) - #2929 Caret in the address bar jumps to the start when I switch keyboard layout (Semen Fomchenkov) - #2938 "Not Secure" label in the address bar is truncated and glued to the domain in translated locales (Semen Fomchenkov) - #2940 Epiphany offers to save a password that it just autofilled itself (after CSV import) (Semen Fomchenkov) - !2145 Update to highlight.js 11.2.0 (Michael Catanzaro) - !2148 web-process-extension: Target active frame when generating password from context menu (John Cardullo) - !2152 Canary: Fix WebKitGTK injected bundle path (Philippe Normand) - !2159 Do not trigger downloads on missing MIME type or failed HTTP responses (John Cardullo) * Translation updates: - Bulgarian (Alexander Alexandrov Shopov) - Catalan (Xavi Ivars) - Chinese (Taiwan) (Chao-Hsiung Liao) - Finnish (Jiri Grönroos) - Kazakh (Baurzhan Muftakhidinov) - Lithuanian (Aurimas Aurimas Černius) - Portuguese (Brazil) (Luiggi Cardoso) - Romanian (Antonio Marin) - Swedish (Anders Jonsson) - Uighur (Abduqadir Abliz)