github ChaoticSi1ence/SlimBrave-Neo v2.3.2
v2.3.2 - Audit at Brave 1.96.59: corrected descriptions and caveats

3 hours ago

Stable Brave moved to 1.96.59 on Chromium 154, so every policy key was re-checked against it. Nothing SlimBrave writes changed — same 78 rows over 74 keys, same values, same presets. What changed is what the tool tells you about them: several descriptions were wrong or overstated, and a few keys now carry a caveat because they do less in current Brave than their label suggested.

Keys that do less than they say — now labelled

These stay in the tool as locks (they cost nothing and guard against Brave changing course), but their labels now say so:

  • Disable Safe Browsing Reporting — no effect in current Brave. Chromium stopped reading this setting, and Brave already keeps extended reporting off.
  • Disable Alternate Error Pages — no effect in Brave. Brave never runs the web-service helper it controls. The old description ("plain local error pages instead of a web-service page") was wrong.
  • Disable Shopping List — no effect in Brave. The feature is off and needs a Google sign-in Brave doesn't have.
  • Disable Brave Playlist, Disable Local AI — off by default on Release. Both are on only in Nightly; the keys keep them off if that changes.

The opposite also happened: Disable Email Aliases now does real work. Brave turned Email Aliases on for Release through a server-side study on 2026-08-27.

Descriptions corrected

  • Disable Payment Method Query: sites are not told "none available" — canMakePayment() is always answered yes and hasEnrolledInstrument() no, so neither reveals whether you saved a card.
  • Disable Brave Rewards: also keeps Brave's ads service off, so no sponsored New Tab Page images and no notification ads. Brave Search's own result ads are not affected. There is still no dedicated Sponsored Ads policy in Brave.
  • Disable Remote Debugging: blocks the brave://inspect remote-debugging toggle (not all of brave://inspect) and takes effect without a restart.
  • Block WebHID: also cuts Brave Wallet's own Ledger hardware-wallet connection.
  • Variations: "critical fixes only" admits only studies Brave marks critical, and none applies to current Brave, so the two Variations rows currently behave alike.
  • Guest mode, password manager, leak detection, spell-check service, developer tools, the Enforce Ad Blocking / Fingerprinting rows, Disable Brave Shields, Safe Sites, Media Router: reworded to match what they actually do in Brave 1.96.
  • macOS script on Linux: the VPN row now says it has no effect on Linux builds, like the Linux script.
  • The leaked Shields exceptions the prefs repair removes are no longer blamed on old SlimBrave versions; no SlimBrave version ever wrote them.

README and SECURITY.md follow suit: the long-removed MediaRecommendationsEnabled is gone from the feature and preset lists, preset contents and minimum Brave versions are corrected, and there is a note on Ad Block Only Mode, which Brave 1.96 ships on by default for English UIs: if you turn it on, brave://policy shows conflict warnings on the keys SlimBrave sets the other way, and SlimBrave's values win.

Known gaps, not changed in this release

Listed in AUDIT.md under What's next: the DoH template is handled differently in automatic mode by the Windows and the Linux/macOS scripts; a Linux machine with only Brave Origin Beta or Nightly also reports a stable Origin; the macOS script does not detect or write Brave Origin's own settings; import stays silent about keys that match no row.

Every key's evidence — the Brave and Chromium source lines at 1.96.59 / 154.0.8037.58 — is in AUDIT.md (PR #29).

Verifying this release

a96f3d41d953b93e3f9093710c056df3a5ff3ded00b6be0e6adc3ca7a4f1a284  SlimBrave.ps1
02fff41b525490ebfa9cd585640aa25979e2aacdc4a8ddfad56259a2ab38c51e  slimbrave-linux.py
6adaa9f5bbed606632818813b8f6ba03ba9a40d31901587639868436846df7de  slimbrave-mac.py
Get-FileHash -Algorithm SHA256 .\SlimBrave.ps1
sha256sum slimbrave-linux.py     # Linux
shasum -a 256 slimbrave-mac.py   # macOS

These are the bytes GitHub serves, checked against the raw URL before publishing.

Don't miss a new SlimBrave-Neo release

NewReleases is sending notifications on new releases.