This Month in Ladybird – September 2026 Ladybird spent a week in September 2026 working with Trail of Bits security engineers through the OpenAI-sponsored Patch the Planet program, using a swarm of frontier OpenAI models to find security issues and craft full exploit chains. The audit produced a considerable security backlog and drove hardening changes, including moving HttpOnly cookie handling to the network process so the browser terminates any renderer requesting that privileged access (PR #12113), tightening macOS and Linux helper sandboxes, and isolating cross-site iframes in separate processes. The browser also added force-dark page rendering via Oklab lightness adjustment in about:settings (PR #11475) and auto-updating content-blocking filter lists such as EasyList (PR #11708). Hello friends In September we spent a week working with Trail of Bits security engineers through Patch the Planet https://blog.trailofbits.com/2026/06/22/introducing-patch-the-planet/ , sponsored by OpenAI. We also cut CPU and memory waste on idle pages, added hardware video decoding on macOS, and got more drawing and animation off the main thread. New settings let you darken pages and use content-blocking filter lists that update automatically. You can paste images into web pages too. :^ Sponsors Ladybird is entirely funded by companies and individuals who believe in the open web. You can see everyone supporting the project on our sponsors page https://ladybird.org/ sponsors , and we’re grateful to all of them. If you’re interested in sponsoring, please contact us mailto:contact@ladybird.org . A week with Trail of Bits The engineers used a swarm of frontier models from OpenAI to find security issues and reported everything they found. We’d never had Ladybird scrutinized at that intensity before. They also crafted a few full exploit chains. The work left us with a considerable security backlog and helped sharpen our security model. Our security model has to hold even if a malicious page exploits a bug and takes over its renderer, the process that handles the page’s HTML, CSS, and JavaScript. Other processes must treat its messages as untrusted and validate the requested operations. Each process needs as little system access as its job allows, and different sites need separate processes. For example, a compromised renderer could ask the browser to read or overwrite any site’s HttpOnly cookies, which are deliberately hidden from page JavaScript. The network process now handles cookies for HTTP responses and WebSocket handshakes, and the browser now terminates any renderer that asks for that privileged access 12113 https://github.com/LadybirdBrowser/ladybird/pull/12113 . We also tightened the helper sandboxes: - macOS: tighter service and file access, plus the hardened runtime to restrict executing code from writable memory 12102 https://github.com/LadybirdBrowser/ladybird/pull/12102 . - Linux: helpers can no longer connect to arbitrary UNIX sockets in the user’s session. Landlock filesystem restrictions are now applied before GPU-driver threads start, so those threads are confined too. Helpers refuse to start without Landlock by default 12099 https://github.com/LadybirdBrowser/ladybird/pull/12099 , 12110 https://github.com/LadybirdBrowser/ladybird/pull/12110 , 12146 https://github.com/LadybirdBrowser/ladybird/pull/12146 . Cross-site iframes can now live in separate processes, and our web test runner exercises that path by default 11794 https://github.com/LadybirdBrowser/ladybird/pull/11794 , 12129 https://github.com/LadybirdBrowser/ladybird/pull/12129 . Normal browsing still isolates at the top level; embedded frames stay with their containing page. Security work is ongoing and will remain part of Ladybird for as long as the project exists. We’re grateful to Trail of Bits for their efforts and OpenAI for supporting the work Dark pages and filter lists Ladybird can now darken pages that don’t offer their own dark theme. Enable force-dark mode in about:settings ; here’s Phoronix with it off and on 11475 https://github.com/LadybirdBrowser/ladybird/pull/11475 . We adjust text, background, and border colors at paint time, while classifying images separately. The photos above keep their original colors. The architecture comes from Chromium; our lightness adjustment uses Oklab, a color space that separates lightness from hue. Ladybird can now download filter lists for content blocking and keep them up to date 11708 https://github.com/LadybirdBrowser/ladybird/pull/11708 . In the new Blocking tab in settings, you can choose EasyList and other lists for ads, tracking, and cookie notices, or add a list URL of your own. Enable automatic updates and Ladybird checks for fresh copies at startup and daily. Changes take effect on the pages you already have open. Hardware decoding and a media process Video playback on macOS now uses hardware decoding through VideoToolbox, which takes much less CPU than decoding with FFmpeg 11665 https://github.com/LadybirdBrowser/ladybird/pull/11665 . It supports H.264, HEVC, VP9, and AV1, using hardware acceleration where available. Decoded frames reach the compositor without copying their pixels. The decoding and playback pipeline for