Files
cromite/docs/FEATURES.md
T

19 KiB

Features

From Bromite

  • customizable adblock filters via user-provided URL (see https://www.bromite.org/custom-filters) (deprecated, replaced by adblock plus)
  • automatically updated adblock filters
  • remove click-tracking and AMP from search results
  • DNS-over-HTTPS support with any valid IETF DoH endpoint
  • always-incognito mode
  • disable all field trials permanently
  • disable smart search by default, allow web search from incognito mode
  • always-visible cookies, javascript and ads site settings from address bar popup
  • remove Play integration binary blobs
  • use CFI on all architectures except x86 and Windows dropped from v117 see https://github.com/uazo/cromite/discussions/292
  • enable trivial auto var init
  • disable media router and remoting by default
  • disable dynamic module loading
  • show warnings for TLSv1.0/TLSv1.1 pages
  • enable site-per-process isolation for all devices with memory > 1GB
  • proxy configuration page with PAC and custom proxy lists support
  • settings to disable custom intents and clear session on exit
  • flags to toggle anti-fingerprinting mitigations for canvas, audio, client rects, webGL and sensor APIs (see full list below for all the new flags)
  • use frozen User-Agent to conceal real model and browser version
  • privacy enhancement patches from Iridium, Inox patchset, Brave and ungoogled-chromium projects
  • security enhancement patches from GrapheneOS project
  • reduced referer granularity
  • block gateway attacks via websockets (partial fix, see this upstream issue)
  • use 64-bit ABI for webview processes
  • make all favicon requests on-demand (supercookie mitigation)
  • enable all network isolation features (PartitionConnectionsByNetworkIsolationKey, PartitionHttpServerPropertiesByNetworkIsolationKey, SplitHostCacheByNetworkIsolationKey, AppendFrameOriginToNetworkIsolationKey, SplitCacheByNetworkIsolationKey, UseRegistrableDomainInNetworkIsolationKey, PartitionSSLSessionsByNetworkIsolationKey, PartitionExpectCTStateByNetworkIsolationKey, PartitionDomainReliabilityByNetworkIsolationKey)
  • ignore enterprise policies that disallow secure DNS
  • ask permission to play protected media
  • disable the DIAL repeating discovery
  • disable RTCGetCurrentBrowsingContextMedia by default
  • disable FLoC and privacy sandbox by default
  • disable feeds
  • disable reporting of certificate errors
  • use pre-defined phone model for client hints and Javascript
  • allow forcing external links to open in incognito
  • disable AGSA by default
  • flag to enable Certificate Transparency
  • allow adding search engines from incognito mode
  • disable predictors
  • disable supervised users
  • disable safety check
  • disable capability to block view-source: URLs
  • disable SegmentationPlatformFeature, OptimizationHints, client hint headers
  • disable AsyncDNS by default
  • customize history expiration threshold
  • disable idle detection
  • HTTPS-only mode enabled by default
  • disable TLS resumption by default
  • strict site isolation and strict origin isolation
  • partition blobs by top frame URL

Cromite-specific features

  • Built-in Adblock Plus patch (issue 84)
  • policy browser patch for the use of enterprise policy patch (issue 191)
    • deactivate safe browsing and extended reporting
    • disabled scroll-to-text-fragment
    • disabled contextual search
    • disabled media router
    • disabled url keyed anonymized data collection
    • disabled translate
    • disabled network prediction
    • disabled sign-in
    • disabled google search side panel
    • disabled automatic https upgrades
  • internal firewall to block all unauthorised calls made from the browser patch (issue 147)
  • show warnings on downloads over HTTP patch
  • lock profile cookie database patch
  • remove support for device memory and cpu recovery patch
  • disable speechSynthesis getVoices API patch
  • viewport Protection patch patch
  • deprecate Data URL in SVGUseElement patch
  • disallow Android App Scheme as referrer patch
  • disable Compression Dictionary Transport patch
  • disable PrivateStateTokens API patch
  • disable GSA by default patch
  • disable GetInstalledRelatedApps API patch
  • disable FirstPartySets and StorageAccessAPI patch
  • disable WebGPU patch
  • disable GamePad API patch
  • remove external https connection from chrome://discards patch
  • links the use of screen.isExtended to WINDOW_MANAGEMENT permission granted by user patch
  • clear CORS Preflight Cache on clearing data patch
  • remove auth header upon cross origin redirect patch
  • disable SHA1 Server Signature patch
  • remove detection of captive portals patch
  • disable devtools remote and custom protocols patch
  • enable Document Open Inheritance Removal patch
  • warning message for unsupported hardware aes patch
  • partition HSTS cache by NAK patch
  • disable password leak detector patch
  • keyboard protection flag patch
  • disable csp reports patch
  • add setting to clear data on exit patch
  • disable visited pseudo class patch
  • disable BackForwardCache patch
  • disable FedCm patch
  • partitioning all cookies by top frame domain patch
  • fingerprint mitigation for AudioBuffer and AnalyserNode patch
from 116.0.5845.111
  • Disable PartnerCustomizations patch #202
  • Add option to disable snapshots patch #201
  • Enable Android Dynamic Performance Framework on renderer patch
from 117.0.5938.63
from 117.0.5938.140
  • Partition MediaDeviceId by default patch
from 118.0.5993.118
from 119.0.6045.106
  • Always clear js and wasm code cache at startup
  • Block Intents While Locked patch
  • Keep Manta Service Disabled patch
  • (Only windows) Hide the presence of the webcam if the user has not given permission #480
from 119.0.6045.124
  • Disable Service and Shared workers on 3P iframe by default patch
from 119.0.6045.160
  • Always allow inspect fallback patch
from 120.0.6099.63
  • Improve the browser sandbox by using the new flags on android patch
from 120.0.6099.199
  • Chrome web store protection patch
  • Enable search engine settings desktop ui in android patch
from 120.0.6099.216
  • Customize selection popup patch
  • Disable Android AppRestrictions patch
  • Add new option in the developer tools settings for deactivating the debugger javascript statement patch
from 120.0.6099.217
  • Enable Gwp Asan in Android patch
from 120.0.6099.230
  • Disable minikin engine
from 121.0.6167.101
  • Disable Read Aloud by default patch
  • Disable Discount Info Api
from 121.0.6167.164
  • Ability to block all popups per site patch
from 122.0.6261.70
  • Expose in settings and activate by default NewTabPage in startup patch
  • Enable percent based scrolling on Windows patch
  • Disable Compose by default patch
  • Offline autofetch by default patch

Windows Cromite-specific features

  • enable Network Service Sandbox by default
  • disable sharing hub
  • disable search for image
  • simpler logging to file
  • disable TabHoverCard images
  • enable File System Access blocklist
  • enable HighEfficiencyMode by default
  • disable annotates on downloads
  • enabled pdf plugin by default

From Bromite

  • browser automatic updates, enabled by default
  • native Android autofill support
  • import/export bookmarks
  • bookmark all tabs from tabs regroup menu
  • allow playing videos in background tabs and disable pause on switching tabs
  • all codecs included (proprietary, open H.264 etc.) dropped from 121.0.6167.143 see https://github.com/uazo/cromite/issues/710
  • AV1 codec support
  • dav1d decoder enabled by default
  • built with official speed optimizations
  • increase number of autocomplete matches from 5 to 10
  • allow changing default download storage location
  • do not ignore save prompt for users without SD cards
  • disable articles and increase number of icons on new tab page
  • adding an URL as bookmark will clear its blocked status for the NTP tiles
  • history support in incognito mode
  • view source of pages
  • sticky desktop mode setting
  • mobile/desktop user agent customization
  • accessibility preference to force tablet UI
  • use Alt+D to focus address bar
  • allow sharing to Bromite
  • UI for crash information collection
  • allow OpenSearch search engine detection in incognito
  • allow OpenSearch search engine detection with paths
  • keyboard dictionary hints in address bar
  • always allow view-source: URLs
  • allow moving navigation bar to bottom
  • add option to use home page as NTP

Cromite-specific features

  • add setting in android to invert tap and long tap patch

You can inspect all functionality/privacy changes by reading the patches

Flags

Flags which have been retired from upstream Chromium but are still available in Cromite.

  • #pull-to-refresh
  • #enable-search-ready-omnibox
  • #darken-websites-checkbox-in-themes-setting
  • #simplified-ntp, enabled by default
  • #enable-text-fragment-anchor, disabled by default
  • #num-raster-threads
  • #enable-image-reader, enabled by default
  • #enable-tab-groups and #enable-tab-groups-ui-improvements
  • #offline-indicator-v2
  • #enable-jxl

New flags:

  • #fingerprinting-canvas-image-data-noise, #fingerprinting-client-rects-noise and #fingerprinting-canvas-measuretext-noise, enabled by default
  • #incognito-screenshot, disabled by default
  • #max-connections-per-host
  • #resume-background-video
  • #ipv6-probing
  • #enable-device-motion and #enable-device-orientation
  • #show-legacy-tls-warnings
  • #save-data-header, disabled by default
  • #export-bookmarks-use-saf, disabled by default
  • #allow-user-certificates, disabled by default
  • #cleartext-permitted, enabled by default, can be used to disable all cleartext-HTTP traffic
  • #omnibox-autocomplete-filtering, can be used to restrict omnibox autocomplete results
  • #disable-external-intent-requests, can be used to disable opening any external app for any URL
  • #enable-userscripts-log, see https://github.com/bromite/bromite/wiki/UserScripts#flags
  • #certificate-transparency-enabled, enabled by default; see https://chromium.googlesource.com/chromium/src/+/master/net/docs/certificate-transparency.md
  • #move-top-toolbar-to-bottom, disabled by default
  • #site-engagement, enabled by default, can be used to disable the automatically-generated icons for most visited sites on the NTP

With chrome://flags/cromite you can see the list of available flags

Site settings

  • webGL, disabled by default
  • images, enabled by default
  • Javascript JIT, disabled by default
  • timezone customization override
  • autoplay, disabled by default
  • webRTC, disabled by default
  • viewport protection, enabled by default