Releases: sheying2013/OpenBrowser
Releases · sheying2013/OpenBrowser
Release list
OpenBrowser v1.0.22
OpenBrowser v1.0.22
中文
- 版本同步与规范:统一更新版本为 v1.0.22,严格同步应用界面显示、npm 配置、Windows 可执行文件元数据与项目文档。
- 网络与代理防护:修复代理加载配置,杜绝特定场景下静默回退直连泄漏真实 IP;规范 Client Hints 报头装配顺序以对齐 Chromium 原生网络栈。
- 内核与自动化防护:清理命令行自动化调试开关(
enable-automation),保持navigator.webdriver原生状态;对齐启动配置模板 User-Agent 与真实内核版本(148.0.7778.165)。 - 作用域与跨域隔离:完善 Web Worker 嵌套 auto-attach 注入时序,确保 Worker 内部 OffscreenCanvas 与主页面指纹严格一致;优化跨 Realm 原型方法与错误对象一致性。
- 显卡与设备画像细化:细化 macOS WebGL 预设池,按 Intel 与 Apple Silicon 架构分别对齐显卡型号与 Client Hints;规范多平台设备参数。
- 界面与图标优化:优化操作栏按钮与浏览器引擎图标矢量渲染,防止界面图标裁切与样式缺失。
English
- Version Alignment: Formally updated to v1.0.22, synchronized across UI display, npm packages, Windows PE metadata, and documentation.
- Network & Proxy Hardening: Fixed proxy launcher configuration to prevent fallback direct connections; restored canonical Chromium wire order for Client Hints headers.
- Kernel & Automation Hardening: Removed automation flags to maintain native
navigator.webdriverbehavior; aligned kernel template User-Agent with the active kernel version (148.0.7778.165). - Worker & Cross-Realm Isolation: Fixed nested auto-attach timing for Web Workers, ensuring OffscreenCanvas WebGL strictly matches main frame persona GPU; improved cross-realm prototype consistency.
- GPU Persona Refinement: Separated macOS WebGL presets by CPU architecture (Intel vs Apple Silicon) to prevent cross-architecture GPU contradictions.
- UI & Icon Rendering: Refined action bar and engine icon SVG rendering to eliminate clipping and display glitches.
下载 / Downloads
| 标签 / Tag | 文件 / File |
|---|---|
| Windows x86_64 · 内置内核 | OpenBrowser-Windows-x86_64-with-kernel.exe |
| Windows x86_64 · 便携包 | OpenBrowser-Windows-x86_64-with-kernel.zip |
| macOS x86_64 · 内置内核 | OpenBrowser-macOS-x86_64.dmg |
| macOS arm64 · 内置内核 | OpenBrowser-macOS-arm64-with-kernel.dmg |
| Ubuntu x86_64 · 内置内核 | OpenBrowser-Linux-x86_64-with-kernel.tar.gz |
标签说明:
with-kernel= 安装包内置独立浏览器内核,运行时无需再下载内核。
OpenBrowser v1.0.21
OpenBrowser v1.0.21 (v1.0.21)
中文
- 版本标识与同步:本发布版本统一为 v1.0.21,严格同步前端界面显示版本、npm 包版本、Windows 可执行文件与产品版本元数据、项目文档徽章及 CI/CD 工作流定义。
- 字体指纹出口全面闭环(P0):Canvas 与 OffscreenCanvas 的
measureText、DOM 元素尺寸(offsetWidth/getBoundingClientRect/getClientRects)、Range 布局测量、SVGgetComputedTextLength/getBBox、document.fonts.check与document.fonts.load全部纳入外平台字体脱敏;修复FontFace构造函数按local()真实目标名解析的致命反转(此前误用外层别名判定,导致正规字体被拒、宿主专属字体反而放行);消除读取FontFace.loaded时突变status的规范违规副作用。 - CSSOM 回显保真:
style.textContent/innerHTML/innerText、CSSRule.cssText、CSSStyleDeclaration.cssText与getPropertyValue('src')一律回显调用方原始输入,杜绝被改写的内部占位符反向暴露注入痕迹;DedicatedWorker 字体层与主线程语义完全同构。 - 媒体轨道标签防泄漏(P0):
MediaStreamTrack.label、getSettings().deviceId、track.clone()/stream.clone()与enumerateDevices()严格同源,彻底封堵getUserMedia返回真实物理硬件名称的穿透路径,同时保持 WebIDL 品牌检查与Illegal invocation错误类型不变。 - Worker WebGPU 去 Proxy 化(P1):DedicatedWorker 的 WebGPU 伪装改为原型访问器 + WeakMap 实现并保留品牌校验;Proxy 包装会破坏 WebIDL 内部私有槽,使
GPUAdapter.prototype.info.call(adapter)抛出Illegal invocation,这本身就是一个可被直接识别的破绽。 - 时区一致性(P0):
engine.js接入resolveProfileTimezone,当出口探测只返回国家码而缺少 IANA 时区时也能推导并注入--time-zone-for-testing,杜绝内核 ICU/V8 裸奔在宿主真实时区而启动页显示代理国时区的时间双面人。 - 代理 Fail-Closed(P0):代理未就绪时默认阻断启动,不再静默回落直连导致真实公网 IP 暴露;如需回落必须显式开启
allowDirectFallback,界面选项同时标注"真实 IP 暴露风险"。 - 启动注入屏障 Fail-Closed:指纹注入失败改为有限重试,重试仍失败时不再导航用户目标站点,改为本地安全错误页并显式上报,避免未伪装的原生指纹裸奔。
- Profile Local State 双写(P1):启动前原子写入
<root>/Local State的intl.app_locale并执行读回校验,补齐 Chromium 最早期 App Locale 读取路径,与Default/Preferences保持一致。 - 多窗口同步特权页降级:
chrome://等特权内部页在多窗口同步中仅做 URL 镜像,不再注入 DOM 脚本或注册Runtime.addBinding;内部页白名单补齐至与主进程一致的 19 项。 - 代理域名解析走 DoH(P1):代理服务商域名优先经 DoH 解析,避免本地 ISP DNS 泄漏;DoH 端点不可达时输出响亮告警并降级系统解析,既不静默泄漏、也不会让受限网络下的代理直接不可用。
- 应用中心下架冲突扩展:移除 Canvas Defender、WebRTC Control、Spoof Timezone、AudioContext Defender 四个推荐项,避免第三方扩展在 DOM 层重复改写 Canvas/时区/WebRTC 与内核指纹注入互相打架(Canvas Defender 在官方商店已下架)。
- 操作栏与平台 UI 修复:操作栏 4 个按钮改用内联同步 SVG 兜底,浏览器内核图标固定 256×256 矢量且不裁切;macOS 下隐藏对其无效的"关闭行为"设置卡片。
- 发布门禁扩容:核心阻断回归套件由 56 项扩充至 64 项,新增"Fingerprint Hardening & Security Barriers"功能域,把字体出口、媒体轨道标签、Worker WebGPU、DoH、Local State 与 Fail-Closed 启动纳入强制门禁。
- 架构边界披露(内核层范围 / 平台边界):TLS Client Hello 与 JA4 指纹、系统级 DNS 解析管线位于 Chromium C++ 网络栈内部,本版本不做脆弱的 JS 层模拟;缺失 CJK 字形仍由系统字体栈原生回退,不做合成 Canvas 度量;
chrome://特权页面受安全沙箱约束保持仅镜像。以上均以 WARN(架构边界)如实标注,绝不伪装为 PASS。
English
- Version Alignment & Synchronization: Formally released as v1.0.21, synchronized end-to-end across UI display labels, npm package definitions, Windows PE file and product version metadata, documentation badges, and CI/CD workflow manifests.
- Font Fingerprint Exit Closure (P0): Canvas/OffscreenCanvas
measureText, DOM element metrics (offsetWidth/getBoundingClientRect/getClientRects), Range layout measurement, SVGgetComputedTextLength/getBBox, anddocument.fonts.check/loadare now all shielded against foreign-platform families. Fixed a critical inversion where theFontFaceconstructor matched the outer alias instead of the reallocal()target (foreign fonts were admitted while legitimate persona fonts were rejected); removed the spec-violating side effect where merely readingFontFace.loadedmutatedstatus. - CSSOM Echo Fidelity:
style.textContent/innerHTML/innerText,CSSRule.cssText,CSSStyleDeclaration.cssText, andgetPropertyValue('src')now echo the caller's original input, so rewritten internal placeholders can no longer expose the injection layer; DedicatedWorker font behaviour is strictly isomorphic to the main thread. - Media Track Label Containment (P0):
MediaStreamTrack.label,getSettings().deviceId,track.clone()/stream.clone()are sourced from the same persona table asenumerateDevices(), closing the path wheregetUserMediareturned real physical hardware names, while preserving WebIDL brand checks and nativeIllegal invocationerror types. - Worker WebGPU De-Proxying (P1): DedicatedWorker WebGPU disguise now uses prototype accessors backed by a WeakMap with brand checks intact; a Proxy wrapper breaks WebIDL internal private slots, making
GPUAdapter.prototype.info.call(adapter)throwIllegal invocation— a directly detectable tell. - Timezone Consistency (P0):
engine.jsnow usesresolveProfileTimezone, so--time-zone-for-testingis derived and injected even when the exit probe only returns a country code. This removes the split where the kernel ICU/V8 silently ran on the host timezone while the start page displayed the proxy country's zone. - Proxy Fail-Closed (P0): A not-ready proxy now blocks startup by default instead of silently falling back to a direct connection that exposes the real public IP; falling back requires the explicit
allowDirectFallbackopt-in, and the UI option is labelled "real IP exposure risk". - Startup Injection Barrier Fail-Closed: Injection failure now retries a bounded number of times and, if it still fails, refuses to navigate to the user's target site, showing a local safety page and raising an explicit event instead of exposing an unspoofed native fingerprint.
- Profile Local State Dual-Write (P1):
intl.app_localeis atomically written to<root>/Local Statewith read-back verification before spawn, covering Chromium's earliest App Locale read path and staying consistent withDefault/Preferences. - Privileged Internal Pages Downgraded in Sync:
chrome://internal pages are mirror-only in multi-window sync — no DOM script injection and noRuntime.addBinding; the internal-page allowlist is aligned to the 19 entries used by the main process. - DoH for Proxy Hostname Resolution (P1): Proxy vendor hostnames resolve over DoH first to avoid local ISP DNS leakage; when the DoH endpoint is unreachable we emit a loud warning and degrade to the system resolver, so nothing leaks silently and restricted networks do not lose proxy connectivity.
- Conflicting Extensions Removed from App Center: Canvas Defender, WebRTC Control, Spoof Timezone, and AudioContext Defender are no longer recommended — stacking third-party DOM-level Canvas/timezone/WebRTC rewrites on top of engine fingerprint injection breaks per-profile consistency (Canvas Defender is also delisted from the store).
- Action Bar & Platform UI Fixes: The four action-bar buttons fall back to synchronous inline SVG, the browser engine icon is a fixed unclipped 256x256 vector, and the close-behaviour card is hidden on macOS where it has no effect.
- Release Gate Expansion: Core blocking regression suites grew from 56 to 64 with a new "Fingerprint Hardening & Security Barriers" domain, gating font exits, media track labels, Worker WebGPU, DoH, Local State, and fail-closed startup.
- Architectural Boundary Disclosure (Kernel-Layer Scope): TLS Client Hello and JA4 fingerprints, plus system-level DNS resolution pipelines, live inside Chromium's C++ network stack; this release does not attempt fragile JavaScript-level emulation for transport traits. Missing CJK glyphs still fall back natively through the system font stack without synthetic Canvas metric manipulation, and privileged
chrome://URLs remain mirror-only under security sandbox policies. These are reported as WARN (architectural boundary) and are never mislabelled as PASS.
下载 / Downloads
| 标签 / Tag | 文件 / File |
|---|---|
| Windows x86_64 · 内置内核 | OpenBrowser-Windows-x86_64-with-kernel.exe |
| Windows x86_64 · 便携包 | OpenBrowser-Windows-x86_64-with-kernel.zip |
| macOS x86_64 · 内置内核 | OpenBrowser-macOS-x86_64.dmg |
| macOS arm64 · 内置内核 | OpenBrowser-macOS-arm64-with-kernel.dmg |
| Ubuntu x86_64 · 内置内核 | OpenBrowser-Linux-x86_64-with-kernel.tar.gz |
标签说明:
with-kernel= 安装包内置独立浏览器内核,运行时无需再下载内核。
OpenBrowser v1.0.20
OpenBrowser v1.0.20
中文
- 修复 v1.0.18/v1.0.19 引入的全屏死循环(严重):这两个版本为了让两个全屏入口各自保留名字,把同一个兼容层拆成了两个独立替换函数;而该兼容层的失败重试会去调用"另一个入口",于是两个替换函数互相调用 —— 页面一旦触发全屏失败(例如没有用户手势时调用
element.requestFullscreen(),真实 Chrome 会 reject),标签页就会陷入无限重试并卡死。现已彻底不再改写全屏入口,两个方法保持内核原样。 - 全屏调用结果不再被伪造:原有兼容层在全屏失败时返回成功(resolve)。实测本内核
requestFullscreen()原生 reject(Permissions check failed),而webkitRequestFullscreen()直接 resolve 但并不真正进入全屏 —— 重试 legacy 会把失败伪装成成功,真实构建不会这样。现在全屏调用的 resolve/reject 与内核原生逐项一致。 - 非法接收者行为(真实缺陷,八个入口):替换函数此前对所有接收者都直接作答,而真实构建会先做品牌检查。用普通对象当接收者时,
speechSynthesis.getVoices、mediaDevices.enumerateDevices、navigator.getBattery、requestFullscreen、document.fullscreenEnabled、visualViewport.width/height、userAgentData.getHighEntropyValues/toJSON、AudioBuffer.copyFromChannel的结果都与原生不同(应为同步抛TypeError: Illegal invocation或返回被拒绝的 Promise)。已改为只服务目标接收者,其余一律交回原生实现。 - 参数校验错误文案对齐:
AudioBuffer.copyFromChannel(null)、copyFromChannel(越界声道)、HTMLCanvasElement.toBlob()缺参数等场景此前抛出的是包装层自造的报错文案;现在一律交回原生实现,错误类型与文案与内核逐字一致(75 个入口的错误接收者矩阵、14 个畸形参数场景均为 0 差异)。 - 回归扩容与变异验证:
selftest:surfacediff增至 8 项断言(属性集合 / 顺序 / Symbol / 描述符属性 / 函数对象身份 / 活动实例形态 / 错误接收者矩阵 / 全屏存活),并修正了一个"测试输入未开启对应伪装导致断言空跑"的问题;变异验证(还原接收者守卫)可立刻失败。 - 版本全链路同步:
package.json、package-lock.json、界面显示、Windows 文件版本信息、README 徽章与 GitHub Actions 发布参数统一为 v1.0.20。
English
- Fullscreen infinite retry introduced in v1.0.18/v1.0.19 (severe) - fixed: those versions split one compatibility shim into two separate replacements so each entry point kept its own name. The shim's failure path called "the other entry point", so the two replacements called each other - any failing fullscreen call (for example
element.requestFullscreen()without a user gesture, which a real Chrome rejects) sent the tab into an endless retry and froze it. The fullscreen entry points are now left completely untouched. - Fullscreen results are no longer faked: the old shim resolved on failure. On this kernel
requestFullscreen()rejects natively (Permissions check failed) whilewebkitRequestFullscreen()resolves without actually entering fullscreen, so retrying through the legacy entry point turned a failure into a success that a real build never reports. Resolve/reject now matches the kernel exactly. - Wrong-receiver behaviour (real defect, eight entry points): the replacements answered for every receiver while a genuine build brand-checks first. With a plain object as the receiver,
speechSynthesis.getVoices,mediaDevices.enumerateDevices,navigator.getBattery,requestFullscreen,document.fullscreenEnabled,visualViewport.width/height,userAgentData.getHighEntropyValues/toJSONandAudioBuffer.copyFromChannelall differed from the native outcome. Replacements now serve only their intended receiver and hand anything else back to the native implementation. - Argument-validation messages aligned:
AudioBuffer.copyFromChannel(null), an out-of-range channel index,HTMLCanvasElement.toBlob()without a callback and similar malformed calls used to raise a message assembled by the wrapper; they are now handed to the native implementation, so error types and text match the kernel word for word (zero differences across a 75-entry wrong-receiver matrix and 14 malformed-argument cases). - Regression widened, mutation-tested:
selftest:surfacediffnow carries 8 assertions (property set, order, symbols, descriptor attributes, function identities, live instances, wrong-receiver matrix, fullscreen liveness), and a case where the test profile did not enable the relevant spoofing - making the assertion vacuous - was found and fixed through mutation testing. - Version synchronization:
package.json,package-lock.json, the in-app label, Windows metadata, README badges, and the GitHub Actions release input are all aligned to v1.0.20.
下载 / Downloads
| 标签 / Tag | 文件 / File |
|---|---|
| Windows x86_64 · 内置内核 | OpenBrowser-Windows-x86_64-with-kernel.exe |
| Windows x86_64 · 便携包 | OpenBrowser-Windows-x86_64-with-kernel.zip |
| macOS x86_64 · 内置内核 | OpenBrowser-macOS-x86_64.dmg |
| macOS arm64 · 内置内核 | OpenBrowser-macOS-arm64-with-kernel.dmg |
| Ubuntu x86_64 · 内置内核 | OpenBrowser-Linux-x86_64-with-kernel.tar.gz |
标签说明:
with-kernel= 安装包内置独立浏览器内核,运行时无需再下载内核。
OpenBrowser v1.0.19
OpenBrowser v1.0.19
中文
- Client Hints 成员可枚举性(真实缺陷):
NavigatorUAData.prototype.getHighEntropyValues与toJSON此前被写成enumerable: false,而真实构建里这两个接口操作是enumerable: true / configurable: true / writable: true。差别直接暴露在Object.keys(NavigatorUAData.prototype)与描述符读取上。已按真实形态修正(真实 Chrome、原生内核、注入后三方取证结果现在逐项一致:Object.keys均列出全部 5 个成员,实例无自有属性)。 - 实例上的影子属性(真实缺陷,两处):
document.fullscreenEnabled/document.webkitFullscreenEnabled与visualViewport.width/height此前被定义成实例自有属性,而真实构建里它们都在原型上(Document.prototype/VisualViewport.prototype)。hasOwnProperty或Object.getOwnPropertyNames(document)一读就能看出差别。现已改到原型上定义、保留原生可枚举性,取值行为不变(视口尺寸实测仍为 756×469,与窗口一致)。 - 静态表面差分回归扩容:
selftest:surfacediff在原有「键集合 / 函数对象别名 / name·length·prototype」之上,新增描述符属性(writable·enumerable·configurable)与 22 个活动实例的自有属性形态 + Symbol 键 + 原型链对比,仍以同一二进制未注入为基线。已两次变异验证:还原旧的共享对象写法、或还原实例影子写法,均立刻失败并退出码 1。 - 修正一条写死错误期望的旧断言:隐身回归里原本要求 Client Hints 成员「非枚举」,与真实构建相反;已改为锁定原生描述符形态。
- 版本全链路同步:
package.json、package-lock.json、界面显示、Windows 文件版本信息、README 徽章与 GitHub Actions 发布参数统一为 v1.0.19。
English
- Client Hints member enumerability (real defect):
NavigatorUAData.prototype.getHighEntropyValuesandtoJSONwere installed withenumerable: false, while a genuine build exposes both interface operations asenumerable: true / configurable: true / writable: true. The gap was readable straight throughObject.keys(NavigatorUAData.prototype)and descriptor inspection. Both now match the native shape - a three-way check (local Chrome, the bundled kernel, and the kernel with injection) reports identical descriptors, all five members listed byObject.keys, and no own members on the instance. - Shadowed instance properties (real defect, two sites):
document.fullscreenEnabled/document.webkitFullscreenEnabledandvisualViewport.width/heightwere installed as own properties of the instance, while a genuine build keeps them on the prototype (Document.prototype/VisualViewport.prototype). A singlehasOwnPropertyorObject.getOwnPropertyNames(document)read exposed that. They are now defined on the prototype with their native enumerability, and the reported values are unchanged (viewport still measures 756x469, matching the window). - Static-surface regression widened:
selftest:surfacediffnow also compares descriptor attributes (writable, enumerable, configurable) and the own-property shape of 22 live instances plus their symbol keys and prototype chains, still against the same binary without the injected layer. Mutation-tested twice: restoring the shared-object version or the instance-shadow version each fails immediately with a non-zero exit. - A stale assertion that encoded the wrong expectation was corrected: the stealth regression used to demand that the Client Hints members be non-enumerable, the opposite of a real build. It now pins the native descriptor shape.
- Version synchronization:
package.json,package-lock.json, the in-app label, Windows metadata, README badges, and the GitHub Actions release input are all aligned to v1.0.19.
下载 / Downloads
| 标签 / Tag | 文件 / File |
|---|---|
| Windows x86_64 · 内置内核 | OpenBrowser-Windows-x86_64-with-kernel.exe |
| Windows x86_64 · 便携包 | OpenBrowser-Windows-x86_64-with-kernel.zip |
| macOS x86_64 · 内置内核 | OpenBrowser-macOS-x86_64.dmg |
| macOS arm64 · 内置内核 | OpenBrowser-macOS-arm64-with-kernel.dmg |
| Ubuntu x86_64 · 内置内核 | OpenBrowser-Linux-x86_64-with-kernel.tar.gz |
标签说明:
with-kernel= 安装包内置独立浏览器内核,运行时无需再下载内核。
OpenBrowser v1.0.18
OpenBrowser v1.0.18
中文
- 全屏入口对象别名(真实缺陷):
Element.prototype.requestFullscreen与Element.prototype.webkitRequestFullscreen此前被装成同一个函数对象,而真实构建里它们是两个不同对象,且后者自带名字webkitRequestFullscreen。注入后requestFullscreen === webkitRequestFullscreen返回true、legacy 入口的name变成requestFullscreen—— 一行相等判断或一次.name读取就能判定环境被改写。现已改为各自独立的替换函数,name/length/prototype与真实构建逐项一致。 - 新增常驻回归:静态表面差分。新增
selftest:surfacediff,遍历页面可达的全部原型(本次 951 个原型、约 9.9k 个表面项),与同一二进制未注入基线逐项对照,锁定四件事:不新增属性、不丢失属性、不新增函数对象别名、name/length/prototype元数据一致。该用例已用变异验证:把旧的共享对象写法还原回去,三项断言立刻失败且退出码为 1。 - CI 侧同步加护栏:隔离回归中新增静态断言,禁止再把同一个替换函数挂到两个入口上。
- 顺带确认(无差异):注入层不泄漏源码 —— 对 Navigator / Screen / Canvas / WebGL / MediaDevices / SpeechSynthesis / Date / Performance / AudioContext / RTCPeerConnection / Element / Document 等原型上的 1,164 个函数逐一执行
Function.prototype.toString,全部返回[native code]。 - 版本全链路同步:
package.json、package-lock.json、界面显示、Windows 文件版本信息、README 徽章与 GitHub Actions 发布参数统一为 v1.0.18。
English
- Fullscreen entry-point aliasing (real defect):
Element.prototype.requestFullscreenandElement.prototype.webkitRequestFullscreenwere installed as the same function object, while a genuine build keeps them distinct and names the legacy onewebkitRequestFullscreen. Under injectionrequestFullscreen === webkitRequestFullscreenreturnedtrueand the legacy entry point carried the standard name - a single equality test or.nameread exposed the rewrite. Each entry point now receives its own replacement with matchingname,lengthandprototype. - New standing regression: static-surface diff. The new
selftest:surfacediffwalks every prototype reachable from the page (951 prototypes, ~9.9k surface entries in this run) and compares it against the same binary without the injected layer, pinning four properties: no added property, no removed property, no new function-object alias, and matchingname/length/prototypemetadata. The case was mutation-tested: restoring the shared-object version fails three assertions and exits non-zero. - CI guard: the isolation suite now fails statically if one replacement is again mounted on two entry points.
- Also confirmed clean: the injected layer leaks no source -
Function.prototype.toStringon 1,164 functions across the Navigator, Screen, Canvas, WebGL, MediaDevices, SpeechSynthesis, Date, Performance, AudioContext, RTCPeerConnection, Element and Document prototypes returns[native code]for every one. - Version synchronization:
package.json,package-lock.json, the in-app label, Windows metadata, README badges, and the GitHub Actions release input are all aligned to v1.0.18.
下载 / Downloads
| 标签 / Tag | 文件 / File |
|---|---|
| Windows x86_64 · 内置内核 | OpenBrowser-Windows-x86_64-with-kernel.exe |
| Windows x86_64 · 便携包 | OpenBrowser-Windows-x86_64-with-kernel.zip |
| macOS x86_64 · 内置内核 | OpenBrowser-macOS-x86_64.dmg |
| macOS arm64 · 内置内核 | OpenBrowser-macOS-arm64-with-kernel.dmg |
| Ubuntu x86_64 · 内置内核 | OpenBrowser-Linux-x86_64-with-kernel.tar.gz |
标签说明:
with-kernel= 安装包内置独立浏览器内核,运行时无需再下载内核。
OpenBrowser v1.0.17
OpenBrowser v1.0.17
中文
- 语音表加载时序修正:
speechSynthesis.getVoices()在真实构建里是异步就绪的 —— 页面第一次同步调用必然拿到空列表,语音表只有在引擎广播就绪之后才可见。此前实现用一个固定 250ms 定时器放行,实测会在同一个内核的原生voiceschanged(267ms)之前就把表交出去(250ms 出表 vs 原生 267ms 事件、302ms 出表),形成“先有表、后有事件”的次序倒置 —— 真实构建不可能出现这种顺序。 - 改为跟随引擎就绪信号:语音表默认扣留,收到内核原生
voiceschanged后立即放行(另设 1000ms 兜底,避免引擎不广播就绪时表永远不可见)。不伪造事件:自造事件的isTrusted恒为false,本身就是特征。 - 实测对齐:修正后伪装 profile 在 258ms 收到原生事件、303ms 出表,与同一二进制原生路径(267ms 事件、302ms 出表)在时序上完全一致;首次同步调用两种路径均返回空列表。
- 回归加固:端到端探针改为在
document_start注入(页面真实观测点)而非页面存活 1.8s 后再注入,新增断言锁定“首次同步为空 + 原生路径仍异步出表 + 出表后voiceURI === name”;CI 侧静态护栏防止有人改回同步返回。 - 版本全链路同步:
package.json、package-lock.json、界面显示、Windows 文件版本信息、README 徽章与 GitHub Actions 发布参数统一为 v1.0.17。
English
- Voice-table load timing fixed: in a real build
speechSynthesis.getVoices()becomes populated asynchronously — the first synchronous call always answers with an empty list, and the table only becomes observable once the engine announces readiness. The previous implementation released the table on a fixed 250ms timer, which on the same kernel fired before the nativevoiceschanged(250ms table vs the native 267ms event and 302ms populated table), producing an ordering a genuine build cannot exhibit. - Now follows the engine readiness signal: the table starts withheld, is released as soon as the kernel's native
voiceschangedarrives, and a 1000ms fallback keeps it from staying hidden forever on a build that never announces readiness. No event is synthesised, because a fabricated one would carryisTrusted === falseand be a tell of its own. - Measured alignment: after the fix the spoofed profile receives the native event at 258ms and exposes the table at 303ms, matching the same binary's native path (event at 267ms, table at 302ms); the first synchronous call returns an empty list on both paths.
- Regression coverage: the end-to-end probe now runs at
document_start— the moment a page actually observes the table — instead of injecting 1.8s into the document's life, with assertions pinning "empty on the first synchronous call", "the native path still publishes asynchronously" and "voiceURI === name", plus a static guard in CI against reintroducing a synchronous return. - Version synchronization:
package.json,package-lock.json, the in-app label, Windows metadata, README badges, and the GitHub Actions release input are all aligned to v1.0.17.
下载 / Downloads
| 标签 / Tag | 文件 / File |
|---|---|
| Windows x86_64 · 内置内核 | OpenBrowser-Windows-x86_64-with-kernel.exe |
| Windows x86_64 · 便携包 | OpenBrowser-Windows-x86_64-with-kernel.zip |
| macOS x86_64 · 内置内核 | OpenBrowser-macOS-x86_64.dmg |
| macOS arm64 · 内置内核 | OpenBrowser-macOS-arm64-with-kernel.dmg |
| Ubuntu x86_64 · 内置内核 | OpenBrowser-Linux-x86_64-with-kernel.tar.gz |
标签说明:
with-kernel= 安装包内置独立浏览器内核,运行时无需再下载内核。
OpenBrowser v1.0.16
OpenBrowser v1.0.16
中文
- Client Hints 完整版本格式修正:
navigator.userAgentData.getHighEntropyValues(['fullVersionList'])里的 GREASE 品牌(如Not_A Brand)此前返回短版本8,而真实 Chrome 在完整列表中一律返回四段式8.0.0.0(已用本机真实 Chrome 与捆绑内核的原生输出双重确认)。现在完整列表使用四段式、精简brands列表仍保持主版本号,两者与真实实现完全一致。 - 回归加固:新增断言同时锁定“精简列表主版本号 + 完整列表四段式”两种格式;真机上验证注入后
brands/fullVersionList/uaFullVersion与内核原生(真实 Chrome 148)逐字段一致。 - 版本全链路同步:
package.json、package-lock.json、界面显示、Windows 文件版本信息、README 徽章与 GitHub Actions 发布参数统一为 v1.0.16。
English
- Client Hints full-version format fixed: the GREASE brand (for example
Not_A Brand) was reported with the short version8insidenavigator.userAgentData.getHighEntropyValues(['fullVersionList']), while a real Chrome always returns the four-part8.0.0.0there (confirmed against both a local Chrome build and the bundled kernel's native output). The full list now uses the four-part form while the reducedbrandslist keeps the major only, matching the real implementation. - Regression coverage: an assertion now pins both formats, and an on-device check confirms
brands,fullVersionListanduaFullVersionmatch the kernel's native (real Chrome 148) output field by field. - Version synchronization:
package.json,package-lock.json, the in-app label, Windows metadata, README badges, and the GitHub Actions release input are all aligned to v1.0.16.
下载 / Downloads
| 标签 / Tag | 文件 / File |
|---|---|
| Windows x86_64 · 内置内核 | OpenBrowser-Windows-x86_64-with-kernel.exe |
| Windows x86_64 · 便携包 | OpenBrowser-Windows-x86_64-with-kernel.zip |
| macOS x86_64 · 内置内核 | OpenBrowser-macOS-x86_64.dmg |
| macOS arm64 · 内置内核 | OpenBrowser-macOS-arm64-with-kernel.dmg |
| Ubuntu x86_64 · 内置内核 | OpenBrowser-Linux-x86_64-with-kernel.tar.gz |
标签说明:
with-kernel= 安装包内置独立浏览器内核,运行时无需再下载内核。
OpenBrowser v1.0.15
OpenBrowser v1.0.15
中文
- macOS WebGL 渲染器格式修正:macOS 预设中有三条仍在使用 Chrome 111 之前的形态(如
ANGLE (Apple, Apple M1, OpenGL 4.1))。Chrome 自 111 起在 macOS 全面改用 ANGLE 的 Metal 后端,当前版本真实输出为ANGLE (Apple, ANGLE Metal Renderer: Apple M1, Unspecified Version)(已用本机 Chrome 实测确认)。旧形态与 UA 声称的 Chrome 版本自相矛盾,是可被直接判定的特征;现改为 Metal 形态,并保留每条预设原本对应的 GPU。 - 回归加固:新增断言要求未启用 persona 的 macOS profile 同样报告 Metal 形态;golden fixture 记录该一次性修正及其理由(与 deviceMemory 从 16 修正为 8 的既有先例一致)。
- 版本全链路同步:
package.json、package-lock.json、界面显示、Windows 文件版本信息、README 徽章与 GitHub Actions 发布参数统一为 v1.0.15。
English
- macOS WebGL renderer format corrected: three macOS presets still used the pre-111 form (
ANGLE (Apple, Apple M1, OpenGL 4.1)). Chrome moved macOS to the ANGLE Metal backend in 111, and a current build reportsANGLE (Apple, ANGLE Metal Renderer: Apple M1, Unspecified Version)(verified against a local Chrome build). The old form contradicted the Chrome version the UA claims and could be checked directly; the presets now use the Metal form while keeping the GPU each one named. - Regression coverage: an assertion now requires non-persona macOS profiles to report the Metal form as well, and the golden fixture records this one-time correction and its rationale (matching the existing precedent for navigator.deviceMemory 16 -> 8).
- Version synchronization:
package.json,package-lock.json, the in-app label, Windows metadata, README badges, and the GitHub Actions release input are all aligned to v1.0.15.
下载 / Downloads
| 标签 / Tag | 文件 / File |
|---|---|
| Windows x86_64 · 内置内核 | OpenBrowser-Windows-x86_64-with-kernel.exe |
| Windows x86_64 · 便携包 | OpenBrowser-Windows-x86_64-with-kernel.zip |
| macOS x86_64 · 内置内核 | OpenBrowser-macOS-x86_64.dmg |
| macOS arm64 · 内置内核 | OpenBrowser-macOS-arm64-with-kernel.dmg |
| Ubuntu x86_64 · 内置内核 | OpenBrowser-Linux-x86_64-with-kernel.tar.gz |
标签说明:
with-kernel= 安装包内置独立浏览器内核,运行时无需再下载内核。
OpenBrowser v1.0.14
OpenBrowser v1.0.14
中文
- 语音指纹跨系统家族修复:未启用设备 persona 的旧 profile 之前按语言挑选语音,会把 macOS 与 Windows 独有语音混在同一份列表中——真实机器不可能同时具备(本机实测 macOS Chrome 210 个语音里 0 个 Microsoft 语音,这类“跨系统家族”正是语音检测项要抓的特征)。现在所有 profile 都按所声称的操作系统收窄语音表:Windows 不再出现 Apple 语音,macOS 不再出现 Microsoft 语音,Linux 只保留 Chrome 自带的 Google 语音。
- 运行时标记扫描回归:媒体设备端到端测试新增一项断言,遍历导航器、屏幕、插件、mimeTypes、语音、WebGL 与 Intl 等页面可读表面,确认输出中不再出现任何产品标记,端到端用例由 5 项增至 6 项。
- 版本全链路同步:
package.json、package-lock.json、界面显示、Windows 文件版本信息、README 徽章与 GitHub Actions 发布参数统一为 v1.0.14。
English
- Cross-OS voice family fixed: profiles without a device persona used to pick voices purely by language, mixing macOS-only and Windows-only voices into one list - a combination no real machine can produce (a local check of macOS Chrome found 210 voices and zero Microsoft ones, and that cross-family mix is exactly what voice-based OS checks look for). Every profile now narrows the voice table to its claimed OS: Windows never reports Apple voices, macOS never reports Microsoft voices, and Linux keeps only Chrome's bundled Google voices.
- Runtime marker sweep: the media-device end-to-end suite now walks the page-readable surfaces (navigator, screen, plugins, mimeTypes, voices, WebGL, Intl) and asserts that no product marker appears anywhere in the output; six end-to-end cases in total.
- Version synchronization:
package.json,package-lock.json, the in-app label, Windows metadata, README badges, and the GitHub Actions release input are all aligned to v1.0.14.
下载 / Downloads
| 标签 / Tag | 文件 / File |
|---|---|
| Windows x86_64 · 内置内核 | OpenBrowser-Windows-x86_64-with-kernel.exe |
| Windows x86_64 · 便携包 | OpenBrowser-Windows-x86_64-with-kernel.zip |
| macOS x86_64 · 内置内核 | OpenBrowser-macOS-x86_64.dmg |
| macOS arm64 · 内置内核 | OpenBrowser-macOS-arm64-with-kernel.dmg |
| Ubuntu x86_64 · 内置内核 | OpenBrowser-Linux-x86_64-with-kernel.tar.gz |
标签说明:
with-kernel= 安装包内置独立浏览器内核,运行时无需再下载内核。
OpenBrowser v1.0.13
OpenBrowser v1.0.13
中文
- 媒体设备标识符泄漏修复:设备 ID 此前用“前缀累加和”派生,只取决于种子前两个字符,导致
env-001/env-002/env-003这类共享前缀的 profile 得到完全相同的音频输入deviceId,可被跨 profile 关联;同时 ID 自带产品前缀,等于自我暴露。现改为整串种子的 SHA-256,输出 64 位小写十六进制,与真实 Chrome 形状一致,且逐 profile 唯一、同一 profile 重启稳定。 - 媒体设备权限面与真实 Chrome 对齐:此前未授予摄像头/麦克风权限时就直接返回设备 ID、分组 ID 与标签;真实 Chrome 在该阶段只返回按类型的空条目(
deviceId/groupId/label全为空),授权后才给出标识符与标签。现在按权限状态返回,无权限时不再泄漏任何标识符。 - 语音指纹产品标记清除:语音噪声模式下
speechSynthesis.getVoices()的voiceURI是ob-voice://…,任何页面都能读取并据此识别。实测真实 Chrome 的voiceURI等于语音名称,现统一为名称本身。 - 回归加固:新增媒体设备端到端测试(未授权面、授权面、重启稳定性、跨 profile 隔离,共 5 项)与“页面可读表面不得出现产品标记”的断言,自测总数增至 94 项。
- 版本全链路同步:
package.json、package-lock.json、界面显示、Windows 文件版本信息、README 徽章与 GitHub Actions 发布参数统一为 v1.0.13。
English
- Media device identifier leak fixed: device ids were derived from a running character sum that depended only on the first two characters of the seed, so profiles sharing an id prefix (
env-001/env-002/env-003) published the same audio-inputdeviceIdand could be linked across profiles; the value also carried a product prefix. Identifiers are now derived from a SHA-256 of the whole seed, emitting 64 lowercase hex characters like real Chrome, unique per profile and stable across restarts. - Media device permission surface aligned with Chrome: the injected layer used to hand out device ids, group ids and labels before any capture permission was granted. Real Chrome returns one empty entry per kind at that stage and only publishes identifiers and labels after a grant. The surface is now permission-gated, so no identifier is exposed without permission.
- Speech fingerprint marker removed: in noise mode
speechSynthesis.getVoices()reportedob-voice://…asvoiceURI, readable by any page. A real Chrome reports the voice name as the URI; the plain name is now used everywhere. - Regression coverage: added a media-device end-to-end suite (withheld surface, granted surface, restart stability, cross-profile isolation) plus an assertion that no page-readable surface carries a product marker - 94 self-tests in total.
- Version synchronization:
package.json,package-lock.json, the in-app label, Windows metadata, README badges, and the GitHub Actions release input are all aligned to v1.0.13.
下载 / Downloads
| 标签 / Tag | 文件 / File |
|---|---|
| Windows x86_64 · 内置内核 | OpenBrowser-Windows-x86_64-with-kernel.exe |
| Windows x86_64 · 便携包 | OpenBrowser-Windows-x86_64-with-kernel.zip |
| macOS x86_64 · 内置内核 | OpenBrowser-macOS-x86_64.dmg |
| macOS arm64 · 内置内核 | OpenBrowser-macOS-arm64-with-kernel.dmg |
| Ubuntu x86_64 · 内置内核 | OpenBrowser-Linux-x86_64-with-kernel.tar.gz |
标签说明:
with-kernel= 安装包内置独立浏览器内核,运行时无需再下载内核。