Firefox 148 Introduces SetHTML for Enhanced XSS Protection

Firefox 148 Introduces SetHTML for Enhanced XSS Protection

First seen 24 Feb 2026, 16:13 UTC News.YcombinatorRedditGbhackersCybersecuritynewsCyberpress 31.3

Article Content

Browse articles
ThreatCluster

Firefox 148 has implemented the new Sanitizer API, which allows web developers to sanitize untrusted HTML before inserting it into the DOM, thereby enhancing protection against cross-site scripting (XSS) vulnerabilities. This update marks Firefox as the first browser to adopt this standardized security feature, with expectations that other browsers will follow suit.

Timeline

2026-02-24
Firefox 148 released with new Sanitizer API for XSS protection