185 built72 underway48 still on the roadmap8lit by this release
0The engine exists
1Reading-grade rendering
2App-grade JavaScript & web APIs
3Media
4Graphics, compositing & the GPU
5Security & multi-process
6The rest of the web platform
7Accessibility, tooling & polish
★The reference browser parity, on our own engine
Hover or drag along the releases above to see the engine at that moment. Each feature lights up in the release that started it and the release that finished it; recent releases also light every feature they worked on.
Sign-ins that stay signed in, a real IndexedDB, and a storage button that shows what sites keep
Cookies are rebuilt from the ground up as one profile-wide store that follows the current cookie standard: what a site sets now comes back on its next page and after a restart, SameSite is enforced the strict way, and third-party cookies get a separate jar per site so they cannot follow you around. Pages get a real IndexedDB and exact Unicode classes in regular expressions. A new button beside the address shows what a site stores on your device, lets you clear it, and decides when it is cleared on its own. Script navigations (location.replace and friends) now really navigate.
A demo site sets an HttpOnly session cookie when you sign in. Before, every request started with an empty cookie jar, so the next page did not know you. Now the cookie comes back on every page of the site, page script never sees it, and it is saved to the encrypted site database. The proof runs as two separate processes: the first signs in and quits, the second starts empty, restores the cookies from the file and loads the site, which greets you by name. The same run against an empty file fails, and the file cannot be read without its key. Twelve cookie laws run over thousands of generated cookie operations on every build, and each catches a deliberately broken store.
After a restartsigned inHttpOnlyhidden from script
See what a site keeps on your device
The storage button: what this site keeps, and when to clear itA quiet note when a page saves 1 MB at onceEvery site in Settings, and the trackers ruleThe inspector: structure, never values
A new button at the right of the address bar shows how much the site you are on keeps: its databases, local storage and cookies, and what the sites it embeds store under it, each marked as a tracker or an embed. Clear any part, or set it to clear when its last tab closes or 30 days after its last write. The inspector shows the shape of what was saved without a single value; values need Touch ID. Everything is read on this device and nothing is sent anywhere.
Shown above100 KBBig-save note1 MB in one burstValuesbehind Touch ID
This offline reading list stores six articles in IndexedDB, reads them back newest first with a cursor, looks them up by tag through an index and counts a key range. Floati only had a placeholder, so the page got no answer and showed nothing. IndexedDB is now complete, saved encrypted with the rest of a site's data, and loads only when a page first uses it.
Checks vs the reference browser6 / 6Cost until usedalmost nothing
Editors, search boxes and tokenizers find words with Unicode property escapes like \p{L} and \p{Script=Greek}. Floati knew only a few of them, so Greek-only found nothing and identifiers were cut at every accented letter. The tables are now measured from the reference browser: 441 properties under 946 spellings, inside character classes too.
Properties441Matchesequal to the reference browser
What changed 25 changes
Privacy & Shields
Cookies are rebuilt to the current cookie standard, as one store for the whole profile. Before, every request made its own empty cookie jar, so a cookie a site set never came back: sign-ins dropped on the next page and carts emptied. Now a cookie set by a page reaches its stylesheets, scripts, fetches and the next visit, and stays through a restart.
Privacy & Shields
SameSite is enforced the strict way: Strict cookies never ride a link from another site, Lax and unmarked cookies ride only a top-level visit by GET, and there is no two-minute window in which a fresh cookie rides a cross-site form post. A site's cookies never go with a request made by another site's page.
Privacy & Shields
Third-party cookies are partitioned, not just blocked: an embedded site gets a separate cookie jar under each site that embeds it, so an embed still works but cannot follow you from one site to the next. The ancestor bit is tracked too, so a frame inside a cross-site frame is treated as cross-site.
Privacy & Shields
Cookies set by page script live at most 7 days, the way the strictest privacy browsers cap them, and never become HttpOnly. Every cookie lives at most 400 days. Script never sees an HttpOnly cookie, and Set-Cookie never reaches a page through a response's headers.
Privacy & Shields
Every cookie rule a modern browser applies: Secure only from secure pages, the __Secure-, __Host- and __Http- name prefixes, SameSite=None needs Secure, a non-secure page cannot overwrite a secure cookie, refusal of cookies for a public suffix, size limits, and fair eviction per site and per partition.
Privacy & Shields
Proven on every build: 12 cookie laws run over thousands of generated cookie operations, among them that HttpOnly is invisible to script, that partitions never leak into each other, that no expired cookie is ever sent, and that a cached document.cookie answer is always exact. Each law catches a deliberately broken store.
Privacy & Shields
Cookies are saved to the same encrypted database as the rest of a site's data, written in batches off the page's thread, so no request waits on the disk. Session cookies never reach the disk, and tracker cookies are not written at all when trackers are set to never keep data.
Privacy & Shields
The real Public Suffix List decides what a site is, for cookies, storage partitions and Shields: all 10,333 rules, passing the list's own test cases. Two blogs on the same hosting service are now separate sites, and a site on a country domain like .co.uk is grouped correctly.
Networking
document.cookie is answered from a cache that stays exact: the store keeps a change counter, and a read with nothing changed returns the last answer without touching the store. Analytics scripts read it in loops; a read takes 0.17 microseconds, faster than before the new store.
Memory & reading
Script navigations navigate: location.assign, location.replace, location.reload and writing location.href, location = url or location.search load the new page, with the page as the one that started it for SameSite. replace takes the current history entry, so Back skips the page that redirected. Before, all of them were silently ignored, so sign-in pages that send you on with a script left you on a blank "Signing in" page.
Tabs & interface
An address typed without http:// for this device or the local network (localhost:5173, 127.0.0.1, 192.168.1.1) opens over http, as dev servers and routers expect, instead of hanging on a secure connection they do not offer.
Tabs & interface
A site storage button sits at the right of the address bar, next to the Floati shield. It shows how much a site keeps once that passes 100 KB, with a dot when it just wrote something, and opens to a breakdown: databases, local storage, cookies, and the embedded sites that store under this site, each marked as a tracker or an embed.
Tabs & interface
When to clear, per site: keep, clear when its last tab closes, or 30 days after its last write. What trackers store can be kept (the default), cleared after 7 days or when the tab closes, or never kept at all, in which case it is refused before it reaches the disk.
Tabs & interface
A quiet note appears when a page saves 1 MB or more in one burst, with a link to see what it saved. It can be turned off from the note or in Settings.
Tabs & interface
Settings has a Site storage section: the total across all sites with its breakdown, a searchable list of sites largest first, the trackers rule, and one button that clears what trackers stored on every site.
Tabs & interface
A storage inspector behind the panel's Details shows each database's stores, record counts, indexes and the shape of its records, and local storage key names, without showing a single value. Values appear only after Touch ID or Windows Hello.
Web APIs & DOM
A real IndexedDB: ordered keys and key ranges, key paths and generators, unique and multi-entry indexes, cursors in every direction, getAll and getAllRecords, transactions that commit on their own and roll back on abort, version upgrades with blocked and versionchange events, deleteDatabase and databases(). Databases are saved encrypted with the rest of a site's data.
Memory & reading
IndexedDB costs nothing until a page uses it: every interface is present with its exact shape from the start, and the engine behind it loads on the first real call. Pages and frames that never open a database pay almost nothing in memory.
Rendering
Regular expressions with Unicode property escapes match exactly: \p{L}, \p{Script=Greek}, \p{ID_Start} and every other property, 441 properties under 946 spellings, measured from the reference browser so the answers are the same. \p now works inside character classes too.
Media
Page elements are instances of their real interfaces: navigator, location, screen, performance, crypto and two dozen other objects answer instanceof and show their interface names, and are the same object each time they are read. Web Audio nodes, message ports and text tracks are linked at creation.
JavaScript & JIT
Reading a DOM property in a loop is more than twice as fast: 184 nanoseconds per read down to 77, and the fastest numeric reads down to 9.7. Loops that touch the DOM used to fall out of the fastest tier on every pass; now they stay in it. Resolving a link's href dropped from 728 to 207 nanoseconds.
Rendering
HTML attributes that take a fixed set of values (a form's method, an input's type and 60 more) read back exactly as the reference browser reads them, including missing, invalid and empty values: 3,796 of 3,796 cases match.
Web APIs & DOM
Links know their parts: protocol, host, hostname, port, pathname, search, hash, origin and the rest read and write on a and area elements by the URL standard's rules. The table API is complete: rows in head, body and foot order, insertRow and deleteRow, captions, cells and indices. Form owners, label.control and fieldset.elements work.
Privacy & Shields
Two old script bugs found by a news site's consent banner: a class whose parent constructor returned its own object lost that object, and a Map kept a -0 key as -0, which made a widely used library replace the built-in Map and break every class that extends it. Both are fixed and covered by laws.
Web APIs & DOM
The measured Web APIs score rose from 36.3 to 42.5 across this release, counted over the whole platform surface against the reference browser, with ad-auction APIs left out by design.
Try it in your browser
Each check runs live in the browser you are reading with. Nothing is sent anywhere.
IndexedDB stores and reads back a recordFloatiChecking
IndexedDB key ranges count in orderFloatiChecking
Unicode script classes in regular expressionsFloatiChecking
Identifier start and continue classesFloatiChecking
Script can set and read its own cookieFloatiChecking