- Block cross‑origin fetch() and XHR for custom protocols unless `corsEnabled:true`, with opaque responses for no‑cors mode;
- Fix several crashes—including invalid HTTP header names in webRequest, PDF generation after a rejected call, autofill popups during window close, and hidden WebContentsView drag regions;
- Backport security patches and upstream fixes for GPU command buffer validation, Skia, ANGLE, and WebRTC