Goodbye innerHTML, Hello setHTML: Stronger XSS Protection in Firefox 148

Firefox 148 becomes the first browser to ship the standardized Sanitizer API, which lets developers sanitize untrusted HTML before inserting it into the DOM. The API offers a browser-level way to strengthen protection against cross-site scripting.

Why it matters

Web developers can use the standardized API to sanitize untrusted HTML at the point it enters the DOM, helping reduce a common source of cross-site scripting risk. Its implementation in Firefox 148 advances support for a shared browser security feature.

Coverage 1 publisher

  1. Mozilla Hacks

    Goodbye innerHTML, Hello setHTML: Stronger XSS Protection in Firefox 148

Articles stay on their publishers’ sites; each link opens the original.