8.5
12 min
Release notes list only what changed since the immediately preceding release. Please read the full release notes page, including intermediate releases, to compare to your current version.
8.5.70 (May 8, 2026)
Improvements
- OS-19445: Updated the set of trusted CA root certificates to match those used by Firefox 140.1.0 ESR. The complete list of trusted CA root certificates is now available from the new cacerts list BrightSign shell command.
Bug Fixes
- OS-17565: Fixed curl CVE-2024-7264
- OS-19093: Fixed CVE-2025-0395
- OS-19771: The play button no longer needs to be pressed twice to start playback when using HTML5 video playback on Vimeo, and players that use MSE
- OS-19797: Fixed XHR requests failing on some web pages when the registry setting disable-http-cache is enabled and a storage path is set for an roHtmlWidget
- OS-19863: Fixed a memory leak caused by method getBVNComponents in devicestatus
- OS-20717, BCN-19028: Fixed a bug where player static IP config is not preserved when applying a setup package with "use current player settings"
8.5.64 (June 5, 2025)
Improvements
- OS-17836: (General) Fixed a local privilege escalation vulnerability (CVE-2025-3925)
- OS-16200, 17236: (General) Upgraded to latest version/branch of OpenEmbedded Dunfell, fixing many CVEs.
- OS-15757: Added support for Prometheus node_exporter (link) to allow player information monitoring.
- OS-16404, OS-16405, OS-16406, OS-16407, OS-16023, OS-16269, OS-13111, OS-17498: Support for Telextext captions.
- OS-17751: (Series 3 and 4) Disabled tooltips and touch selection menu in Chromium.
- OS-18002: (General) Removed all hidden sections from the registry_dump API.
- OS-18181: (General) Chromium has changed the way it caches XHR requests, which can cause a buildup of files resulting in issues accessing a portion of the SD card. To address this, we have added a new html > disable-http-cache registry value which users can set to 1 to disable HTTP caching.
Supervisor (2.0.23) and DWS (0.1.51) and default-autorun (0.0.87) (OS-18585)
- BCN-17638: Reboot is now faster when a WiFi module is present but not configured with internet access.
- PE-600: Fixed issue where Option 43 did not send some headers when "ru" registry is not set.
- BCN-15698: Added search capability to the Log tab of the local and remote DWS.
- BCN-15944: Removed the BSN.Cloud networking setup type from On-Device Setup.
- BCN-16662: Fixed an issue where the log search would hang if the search text has too many spaces.
- BCN-16783: Fixed an issue where the log search would hang for an extended period when the input field doesn’t contain anything.
- BCN-17017: Added the networking > ldws_certs_path registry value to override the location of the DWS certs for HTTPS.
Bug Fixes
- OS-16467: (General) Non-printable characters returned from getNeighborInformation() response will now be ignored (instead of generating an exception error).
- OS-18046: (Series 4 and earlier) A video will now be classified as 4K if either the height or width exeeds 1920 and it's height*width does not already exceed the height*width limit for HD content.
- OS-18636: (General) Removed teardrop icon which appeared with a long press touch.
8.5.53.2 (Oct 17, 2024)
Improvements
- OS-17836: (General) Fixed a local privilege escalation vulnerability (CVE-2025-3925)
8.5.53 (Sep 18, 2024)
Improvements
- OS-16200: (All) Upgraded to latest version of OpenEmbedded, fixing many CVEs.
- OS-16143: (All) Added libcurl security fixes (CVE-2023-38545 and CVE-2023-38546).
Bug Fixes
- OS-16196: (All) Fixed an issue where a crash would occur when trimming incorrect HTTP responses during network diagnostics.
- OS-16251: (All) Fixed an issue where a crash would occur when the virtual keyboard was enabled in HtmlWidgetQt.
- OS-16298: (All) Fixed an issue where a player using AEST does not correctly change time with DST.
- OS-16310: (All) Fixed a time zone issue where local times in Mexico would be incorrect.
- OS-16350: (All) Fixed an issue where a virtual keyboard would not be initialized properly and thus not display.
- OS-16422: (All) Fixed an issue where user variables would not be properly set when the value is an empty string.
Supervisor (2.0.20), DWS (0.1.51) and Default Autorun (0.0.80) Updates (OS-16336, OS-16603, OS-16746)
- BCN-14806: Cleaned up supervisor REST API logging to make it easier to find important information.
- BCN-15316: Fixed a regression in which the Chromium debugging section was not being displayed on the DWS Diagnostics screen.
- BCN-15244: Added the ability for users to select debug logging levels in addition to the existing INFO, WARNING and ERROR levels.
- BCN-15081: LFN splash screen now shows IP address for wifi and ethernet.
- BCN-15321: DWS improvements when displaying EDID information.
8.5.47 (Oct 05, 2023)
Improvements
- OS-14162: (General) Ensured that the BrightSign "verified" header is always sent to prevent spoofing.
- OS-15988: (XD4/XT4) Added “tun0” network interface to network configuration.
Bug Fixes
- OS-14699: Fixed an issue where the player would crash when attempting to use @brightsign/serialport.
- OS-15414: (XD4/XT4) Fixed an issue where a screen does not rotate as expected but instead reverts to the default landscape orientation.
- OS-15551: Fixed a Chromium iframe memory leak related to QtWebengine.
- OS-15686: Fixed a layering issue with certain CSS animations and Z-order.
- OS-15722: Fixed an issue where the player does not properly perform IPv6 Stateless Address Autoconfiguration (SLAAC).
- OS-15731: Fixed an issue where the browser fails to hide an already playing video when the “hwz” attribute is set to “z-index:1”.
- OS-15972: (General) Fixed an issue where hostconfiguration getConfig() returns “true” for loginPassword even when no password is set. If no password is set, it should return “false”.
- OS-16105: (HD4/LS4/XD4/XT4) Fixed an issue where HTML video would be hidden behind a black rectangle.
Supervisor (2.0.17) and DWS (0.1.49) Updates
- BCN-9959: Enabled access to a player’s registry via the remote and local DWS.
- BCN-14338: Fixed an issue that prevented USB700 USB-C and Cellular Modem USB-A from connecting properly.
- BCN-14422: Added the ability to format both SSD and USB stick media when it is not formatted or mounted correctly. This can be found under the Diagnostics tab > Format Storage.
- BCN-14781: Added support for the upload and download of binary (non-text) files through the rDWS, including support for files of type ‘application/octet-stream’.
- BCN-15069: Created a new DWS UI for Telnet/SSH.
8.5.36 (Apr 26, 2023)
Improvements
- OS-14731: Upgraded to latest packages per OpenSSL security advisory.
Bug Fixes
- OS-13160: Fixed an issue where DHCP IP in IPv6 was bound to the DUID and not the MAC Address.
- BCN-13310: Fixed support for remote directory creation.
8.5.33 (Dec 05, 2022)
Improvements
- OS-13924: Forced redraw if HTML widget is moved
- OS-14000: HTML widget storage quota can now be made large
Bug Fixes
- OS-14166: Fixed non-HWZ video on 4K242, 4K1042, and 4K1142 models
- OS-14238: Fixed simultaneous video playback from multiple HTML widgets
8.5.31 (Oct 24, 2022)
Notable Changes
- OS-12400: Node upgraded to version 14.17.6
- OS-12444: Chromium upgraded to version 87.0.4280.144
- OS-13121, OS-13172: Applied numerous CVE fixes (Merged all Chromium CVE fixes up to Chromium99): CVE-2021-0129, CVE-2021-45960, CVE-2021-46143, CVE-2022-22822-27, CVE-2022-23852, CVE-2022-23990, CVE-2022-25235, CVE-2022-25236, CVE-2022-25313-5, CVE-2021-42374, CVE-42376, CVE-2020-36254, CVE-2021-27218, CVE-2021-27219, CVE-2021-28153, CVE-2021-3995, CVE-2021-3996, CVE-2021-45078, CVE-202-23903, CVE-2020-10531, CVE-2021-33560, CVE-2021-40528, CVE-2021-36976, CVE-2021-3658, CVE-2022-23308, CVE-2022-1271, CVE-2022-0204, CVE-2022-0563, CVE-2021-3541, CVE-2021-3517, CVE-2021-30553, CVE-2021-30569, 1204814 and 1197786, CVE-2021-30560, CVE-2021-30627, CVE-2021-30618, CVE-2021-30603, CVE-2021-30585, CVE-2021-30559, CVE-2021-30547, CVE-2021-30522, CVE-2021-21227, CVE-2021-30513, CVE-2021-21231, CVE-2021-30513, CVE-2021-30518, CVE-2021-30513, CVE-2021-30515, CVE-2021-21231, CVE-2021-21207, CVE-2021-21230, CVE-2021-21227, CVE-2021-21223, CVE-2021-21203, CVE-2021-21204, CVE-2021-21202, CVE-2021-21214, CVE-2021-21221, CVE-2021-21206, CVE-2021-21220, CVE-2021-21160, CVE-2021-21156, CVE-2021-21188, CVE-2021-21195, CVE-2021-21198, CVE-2021-21175, CVE-2021-21193, CVE-2021-21190, CVE-2021-21160, CVE-2021-21165, CVE-2021-21157, CVE-2021-21148, CVE-2021-21137, CVE-2021-21153, CVE-2021-21138, CVE-2021-21119, CVE-2021-21140, CVE-2021-21140, CVE-2021-21120, CVE-2020-16044, CVE-2020-16044, CVE-2020-16044, CVE-2021-21146, CVE-2021-21114, CVE-2020-16042, CVE-2020-16030, CVE-2020-16027, CVE-2020-16016, CVE-2020-16040, CVE-2020-16034, CVE-2020-16028, CVE-2020-16024, CVE-2020-16022, CVE-2020-16014, CVE-2020-16011, CVE-2020-16008
- Fixed CVE-2021-44532 in TLS/node
- The Chromium remote inspector is disabled by default on 8.5 release, even when it is enabled by roHtmlWidget enable_inspector flag, or roHtmlWidget.StartInspectorServer. An extra registry value has been added (”enable-web-inspector” in the “html” registry section) to enable the inspector. This ensures that users do not unintentionally enable the remote inspector on production software, which is not secure and may increase memory usage.
- Chromium has dropped support for desktop style scrollbars. BrightSign OS 8.5 is shipped with overlay scrollbars. Overlay scrollbars overlay on graphics and are only displayed when a page is scrolled. They disappear when the page is still.
- Chromium87 uses separate JavaScript contexts for data URLs. It is no longer possible to inject JavaScript from the data URL and access window context.
- Data URLs no longer share the same URL domain with the origin domain. It is no longer possible to access cross site data from data URLs.
- Chromium has added support to view remote device screen through inspector view. This is not supported on BrightSign devices due to architectural differences between desktop Chromium and BrightSign.
- Chromium has added more stringent security policies around cross site requests. Some of these security options can be disabled if needed. But, unlike our security_params (roHtmlWidget.security_params), these security options cannot be disabled per instance. We have added an “html” → “disable-web-security” registry option to disable these security checks. This change takes effect after a reboot.
Improvements
- OS-12211: Added UseInitiatorAddressFromPacket() method to BSCECTransmitter
- OS-12538: Clipped input from SetCursorPosition to resolution
- OS-12767: BrightSign video player has been extended to play in-memory, or partially in-memory blobs from HTML video elements
- OS-12943: Added a recipe for NodeJS epoll package and included it in mission image
- OS-13010: HDCP2.2 beta functionality is now disabled by default. This can still be enabled if users wish to experiment with HDCP2.2
- OS-13022: roUrlTransfer no longer allows curl_debug in encrypted BrightScript
- OS-13089: Fixed black screen flash when switching between videos of different resolutions
- OS-13154: Raised mouse move events in HTML widget
- OS-13206: HTML popups can now be accepted or rejected through script
- OS-13363: Ensured that removing the last item invalidates the roList index
- OS-13403: Re-instated support for Elo touchscreens with a custom binary driver
- OS-13512: Added Reassociate function that can safely re-connect wifi connection without losing user configurations .
- OS-13705: Made @brightsign/pointercalibration startCalibration arguments optional
- OS-13764: Reinstated the ability to disable mouse input on roHtmlWidget
- OS-13781: Web inspector now requires a registry entry to enable it
- OS-13512: Provided Reassociate() method for scripts to reconnect WiFi without losing user configurations
Bug Fixes
- OS-12831: Added a fix for video capture being erroneously selected when playing back a video stream
- OS-13053: Fixed video location mismatch error
- OS-13741: Added focus management for overlapping widgets
- OS-13117: Added a registry option to enable --allow-running-insecure-content
- OS-13827: Avoid flushing cache when mapping assetpool - can cause problem with active connections