SeaMonkey is still not patched for the recent WebP security disaster.
Fortunately, until it is patched, I can just turn it off in about:config with image.webp.enabled to false.
It’s a bad vulnerability and I spent a few days sort of ignoring SeaMonkey except to deal with my E-Mail, since that doesn’t open remote content by default anyway, then I found this.
To test it, I took a WebP file and dropped it on SeaMonkey before and after. After turning WebP off, it offered to “download” the file somewhere instead of opening the image with its native WebP support.
This is a really terrible image format.
I decided to turn it off in LibreWolf (Firefox fork) too and see if it breaks anything I use terribly. Already, I see an improvement. With WebP and AVIF turned off in LibreWolf, Reddit has gone back to sending me real JPEG files!
In Firefox/LibreWolf you can also turn off AVIF (which SeaMonkey doesn’t support yet) with image.avif.enabled to false.
The way Google writes bad code, if it doesn’t end up breaking the Web for me it’ll just be more Web browser junk I turn off now.
Jamie Zawinski called WebP “another turd in the punchbowl” 12 years ago. ⬆