Skip to content

Browser v2026.7.0

Choose a tag to compare

@bre-deploy bre-deploy released this 23 Jul 16:49
adf0337

What's Changed

  • New installs will now prompt users to allow Bitwarden to manage their browser password manager settings
  • Added new save and fill flow
  • Added direct Keepass import
  • Various under-the-hood improvements and minor bug fixes

💙 Community Highlight

  • [PM-33285] Enhance privacy in password leak detection with response padding by @TheDcoder in #19439
  • [PM-35288] feat: auto-close sso tab after authentication completes by @sander-adamse in #20213
  • [PM-36443] fix microsoft totp autofill by @danysigha in #20481
  • [PM-38109] fix(browser): use direct clipboard API when popup has DOM access by @RobinAngele in #20859
  • [PM-38123] [bug] Preserve 1Password archive state on 1pux import (closes #20694) by @999purple999 in #20867
  • [PM-39177] fix(libs): correct various typos in shared libraries and documentation by @luojiyin1987 in #21320
  • [PM-39180] fix(browser): correct various typos in browser extension by @luojiyin1987 in #21323

:shipit: Feature Development

🐛 Bug fixes

  • [PM-39731] Hotfix: Revert "[Shared Unlock] [PM-34508] Default enable native messaging permission on browser (#19907) by @mzieniukbw in #21559
  • [PM-32445] Extension Scrollbar Fix by @rr-bw in #20478
  • [PM-37752] - fix collections control when extension loses focus by @jaasen-livefront in #20812
  • [PM-34926] Allow single-character CJK vault searches by @jaasen-livefront in #21013
  • [PM-38581] - disable drag for single custom fields by @jaasen-livefront in #21136
  • [PM-38409] - update custom field value on reorder by @jaasen-livefront in #21137
  • Auth/PM-35783 - Fix Org Invite Policy State Pollution and State Clearing Issue by @JaredSnider-Bitwarden in #21218
  • [PM-38608] [PM-38560] Fix diacritic normalization and multi-word query handling in searchCiphersBasic by @nick-livefront in #21232
  • [PM-38836] harden calculateSubFramePositioning by @audreyality in #21282
  • [PM-39200] - fix notification bar behavior with save and fill by @jaasen-livefront in #21351
  • PM-37236 resolved password button issue on browser by @bmbitwarden in #21359
  • fix(platform): remove hardcoded vault.bitwarden.com checks in getSendUrl and getScimUrl by @addisonbeck in #21373
  • [SM-1483] Fix self-hosted environment URLs in Secrets Manager config by @vincentsalucci in #21375
  • [PM-39204] Add extra spacing to vault items when batch bar is visible by @nick-livefront in #21390
  • [SM-1993][CL-1227] Fix textarea height and fix SM button spacing by @vleague2 in #21417
  • [PM-39392] Use readonly styles for fields intended to be readonly by @vleague2 in #21425
  • [CL-1228] hide actions container if empty and always render button outside by @BryanCunningham in #21440
  • [PM-39429] remeasure bulk actions bar width when actions change by @BryanCunningham in #21443
  • [PM-39447] [Shared Unlock] Shared unlock stuck on lock component by @quexten in #21446
  • [PM-37932] Make IPC content script re-injection idempotent by @coroiu in #21451
  • [PM-38940] Close Firefox/Safari Permissions-Policy gaps via webRequest by @bensbits91 in #21466
  • [PM-7036] Add support for latest LogMeOnce CSV import format, add folder mapping by @mcamirault in #21473
  • manually recompile select css by @BryanCunningham in #21488
  • [CL-1225] Berry should hide when count is 0 in toggle group by @vleague2 in #21491
  • [PM-39349]] - make ssh key cipher fields readonly by @jaasen-livefront in #21505
  • reduce select label font size by @BryanCunningham in #21525
  • [PM-39695] Send fields are unexpectedly editable and changes cannot be saved by @harr1424 in #21542
  • Revert "[PM-38760] Recursively create directory when writing manifest (#21141)" by @addisonbeck in #21568
  • [PM-39380] Bitwarden unencrypted JSON files containing cipher keys prevent import by @harr1424 in #21587
  • [PM-36888] Do auto confirm when setting is enabled by @BTreston in #21614
  • [PM-31138] Perform full sync on other clients after upgrade key rotation by @quexten in #21628
  • [PM-39556] Fix access selector not saving changes when the dialog field is modified by @BTreston in #21640
  • [PM-37196] Tooltip expand max-width by @JaredScar in #21646
  • Revert "[Shared Unlock] [PM-34508] Default enable native messaging pe… by @quexten in #21687
  • [PM-39977] Fix broken shared unlock for browser-desktop in non-dev mode by @quexten in #21688
  • [PM-39570] use correct fill for bup logo by @BryanCunningham in #21694
  • Prevent connect to desktop in ipc background if native messaging permission is missing by @quexten in #21702
  • [PM-38392] Route password-protected Send saves through the SDK by @adudek-bw in #21725
  • fix(biometrics): Biometric unlock does not work over SDK by @quexten in #21730
  • fix(unlock): Biometric unlock shows error dialog when cancelling by @quexten in #21731
  • fix(vault): archive and unarchive missing from bulk bar for org items by @nick-livefront in #21741
  • Render native form control UI in dark theme with color-scheme: dark by @maxkpower in #21771
  • [CL-1263] Increase active bottom navigation label font weight by @BryanCunningham in #21772
  • fix(browser): Fix biometrics setup and connection issues by @quexten in #21782
  • [PM-38940] Cherry-pick to rc: Fix Permissions-Policy VULN-582 (#21466) by @bensbits91 in #21834
  • [PM-40303] Fix logout when underprivileged user accesses Manage Send policy by @harr1424 in #21836
  • [PM-40303] Cherry-pick to rc: Fix user logout when missing permissions by @harr1424 in #21846
  • [PM-40236][RC] Logging out throws error mid-logout due to a race condition. User left in locked state by @mzieniukbw in #21869

⚙️ Maintenance

📦 Dependency Updates

  • [deps] UI Foundation: Update @storybook/test-runner to v0.24.4 by @renovate in #17854
  • [PM-35903] Update clients to node 24 by @dani-garcia in #20400
  • Update sdk-internal to 0.2.0-main.843 by @bw-ghapp in #21233
  • [deps] Platform: Update @babel/core to v7.29.6 [SECURITY] by @renovate in #21277
  • Update sdk-internal to 0.2.0-main.849 by @bw-ghapp in #21299
  • [PM-39351][PM-39353][PM-39369] Update Angular to 21.2.17 by @vleague2 in #21377
  • Update sdk-internal to 0.2.0-main.857 by @bw-ghapp in #21393
  • [deps] Platform: Update webpack-dev-server to v5.2.5 [SECURITY] by @renovate in #21404
  • [deps]: Update codecov/codecov-action action to v7 by @renovate in #21409
  • Update sdk-internal to 0.2.0-main.859 by @bw-ghapp in #21475
  • Update sdk-internal to 0.2.0-main.870 by @bw-ghapp in #21482
  • Update sdk-internal to 0.2.0-main.872 by @bw-ghapp in #21651
  • [deps]: Update dtolnay/rust-toolchain digest to 4be7066 by @renovate in #21667
  • Update sdk-internal to 0.2.0-main.883 by @bw-ghapp in #21686
  • chore(deps): move rand to KM Renovate ownership by @addisonbeck in #21719
  • Fix lockfile by @dani-garcia in #21763

🎨 Other

  • [PM-39008] Do not show save new password inline menu over generate password menu if a new password has not been filled by @jprusik in #21244
  • Bump client version(s) by @github-actions in #21271
  • Auth/Add CLAUDE.md files to angular/src/auth and common/src/auth on file organization + barrel files by @JaredSnider-Bitwarden in #21283
  • Autosync Crowdin Translations for browser by @bw-ghapp in #21380
  • Disable self import rule by @quexten in #21410
  • Autosync Crowdin Translations for browser by @bw-ghapp in #21507
  • Add claude snap permissions rule by @quexten in #21514

New Contributors

Full Changelog: browser-v2026.6.1...browser-v2026.7.0