From a0c7704c4b8fbee80d9e49d84041b62bd895d4c4 Mon Sep 17 00:00:00 2001
From: CloakHQ
Date: Mon, 6 Apr 2026 01:51:50 +0200
Subject: [PATCH] =?UTF-8?q?release:=20v0.3.20=20=E2=80=94=2048=20patches,?=
=?UTF-8?q?=20WebRTC=20IP=20spoofing,=20proxy=20signal=20removal?=
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
---
CHANGELOG.md | 12 ++++++++++++
README.md | 22 +++++++++++-----------
cloakbrowser/_version.py | 2 +-
cloakbrowser/config.py | 4 ++--
js/README.md | 2 +-
js/package.json | 2 +-
js/src/config.ts | 4 ++--
7 files changed, 30 insertions(+), 18 deletions(-)
diff --git a/CHANGELOG.md b/CHANGELOG.md
index 9272170..6fcf774 100644
--- a/CHANGELOG.md
+++ b/CHANGELOG.md
@@ -6,6 +6,18 @@ Changes are tagged: **[wrapper]** for Python/JS wrapper, **[binary]** for Chromi
---
+## [0.3.20] — 2026-04-06
+
+- **[binary]** Upgrade Linux x64 build to 145.0.7632.159.9 — 48 source-level C++ patches (up from 42)
+- **[binary]** 6 new patches: WebRTC IP spoofing, proxy signal removal, network timing normalization, WebGL accuracy improvements
+- **[binary]** New `--fingerprint-webrtc-ip` flag — spoof WebRTC ICE candidate IPs to match your proxy exit IP
+- **[binary]** Proxy detection signals eliminated — timing, headers, and network metadata normalized when proxy is active
+- **[binary]** WebGL rendering accuracy improvements for headed mode
+- **[wrapper]** Auto-inject `--fingerprint-webrtc-ip` when `geoip=True` — uses resolved exit IP from GeoIP lookup
+- **[wrapper]** Rewrite `cloakserve` as CDP multiplexer with per-connection fingerprint seeds and connection tracking
+- **[wrapper]** Humanize keyboard improvements — better behavioral stealth for typing interactions (thanks [@evelaa123](https://github.com/evelaa123))
+- **[meta]** Bump GitHub Actions dependencies
+
## [0.3.19] — 2026-03-30
- **[binary]** Upgrade Linux x64 build to 145.0.7632.159.8 — 42 source-level C++ patches (up from 33)
diff --git a/README.md b/README.md
index 0ab77ea..131a4a4 100644
--- a/README.md
+++ b/README.md
@@ -40,7 +40,7 @@ Drop-in Playwright/Puppeteer replacement for Python and JavaScript.
Same API, same code — just swap the import. 3 lines of code, 30 seconds to unblock.
-- **42 source-level C++ patches** — canvas, WebGL, audio, fonts, GPU, screen, automation signals, CDP input behavior
+- **48 source-level C++ patches** — canvas, WebGL, audio, fonts, GPU, screen, WebRTC, network timing, automation signals, CDP input behavior
- **`humanize=True`** — human-like mouse curves, keyboard timing, and scroll patterns. One flag, behavioral detection passes
- **0.9 reCAPTCHA v3 score** — human-level, server-verified
- **Passes Cloudflare Turnstile**, FingerprintJS, BrowserScan — tested against 30+ detection sites
@@ -128,16 +128,16 @@ Open [http://localhost:8080](http://localhost:8080). Create a profile. Click **L
---
-## Latest: v0.3.19 (Chromium 145.0.7632.159.8)
+## Latest: v0.3.20 (Chromium 145.0.7632.159.9)
-- **`humanize=True`** — one flag makes all mouse, keyboard, and scroll interactions behave like a real user. Bézier curves, per-character typing, realistic scroll patterns. Two presets: `default` and `careful`
-- **CDP input behavior mimicking** — input events sent via CDP now produce the same signals as real user interactions. 4 source-level patches covering pointer, keyboard, and mouse behavior
-- **Native locale spoofing** — new C++ patch replaces detectable CDP-level locale emulation
-- **WebGPU fingerprint hardening** — adapter features, limits, and device ID spoofed for cross-API consistency
-- **42 fingerprint patches** (Linux x64) — all 4 platforms on Chromium 145
+- **48 fingerprint patches** (Linux x64) — 6 new patches covering WebRTC IP spoofing, proxy signal removal, and network timing normalization
+- **WebRTC IP spoofing** — `--fingerprint-webrtc-ip=auto` resolves your proxy's exit IP and spoofs WebRTC ICE candidates. Auto-injected when using `geoip=True` (no extra network call)
+- **Proxy signal removal** — DNS/connect/SSL timing zeroed, proxy cache headers stripped, Proxy-Connection header leak removed
+- **`cloakserve` CDP multiplexer** — rewritten as a multi-connection CDP proxy with per-connection fingerprint seeds
+- **Humanize CDP isolation** — keyboard events now use isolated worlds and trusted dispatch for better behavioral stealth
+- **`humanize=True`** — one flag makes all mouse, keyboard, and scroll interactions behave like a real user. Bézier curves, per-character typing, realistic scroll patterns
- **Stealthy with zero flags** — binary auto-generates a random fingerprint seed at startup. No configuration required
- **Timezone & locale from proxy IP** — `launch(proxy="...", geoip=True)` auto-detects timezone and locale
-- **WebRTC IP spoofing** — `--fingerprint-webrtc-ip=auto` resolves your proxy's exit IP and spoofs WebRTC ICE candidates. Auto-injected when using `geoip=True` (no extra network call)
- **Persistent profiles** — `launch_persistent_context()` keeps cookies and localStorage across sessions, bypasses incognito detection
See the full [CHANGELOG.md](CHANGELOG.md) for details.
@@ -222,7 +222,7 @@ CloakBrowser is a thin wrapper (Python + JavaScript) around a custom-built Chrom
3. **Every launch** → Playwright or Puppeteer starts with our binary + stealth args
4. **You write code** → standard Playwright/Puppeteer API, nothing new to learn
-The binary includes 42 source-level patches covering canvas, WebGL, audio, fonts, GPU, screen properties, hardware reporting, automation signal removal, and CDP input behavior mimicking.
+The binary includes 48 source-level patches covering canvas, WebGL, audio, fonts, GPU, screen properties, WebRTC, network timing, hardware reporting, automation signal removal, and CDP input behavior mimicking.
These are compiled into the Chromium binary — not injected via JavaScript, not set via flags.
@@ -1019,7 +1019,7 @@ A: Yes. Pass `proxy="http://user:pass@host:port"` to `launch()`.
| Feature | Status |
|---------|--------|
-| Linux x64 — Chromium 145 (42 patches) | ✅ Released |
+| Linux x64 — Chromium 145 (48 patches) | ✅ Released |
| macOS arm64/x64 — Chromium 145 (26 patches) | ✅ Released |
| Windows x64 — Chromium 145 (33 patches) | ✅ Released |
| JavaScript/Puppeteer + Playwright support | ✅ Released |
@@ -1043,7 +1043,7 @@ All releases are signed for supply chain verification.
```bash
# Verify GPG signature (binary release tag)
gpg --keyserver keyserver.ubuntu.com --recv-keys C60C0DDC9D0DE2DD
-git verify-tag chromium-v145.0.7632.159.8
+git verify-tag chromium-v145.0.7632.159.9
# Verify GitHub binary attestation (Sigstore)
gh attestation verify cloakbrowser-linux-x64.tar.gz --repo CloakHQ/cloakbrowser
diff --git a/cloakbrowser/_version.py b/cloakbrowser/_version.py
index 08aad71..8b971c7 100644
--- a/cloakbrowser/_version.py
+++ b/cloakbrowser/_version.py
@@ -1 +1 @@
-__version__ = "0.3.19"
+__version__ = "0.3.20"
diff --git a/cloakbrowser/config.py b/cloakbrowser/config.py
index 38008ba..ccbf59f 100644
--- a/cloakbrowser/config.py
+++ b/cloakbrowser/config.py
@@ -15,10 +15,10 @@ from ._version import __version__
# CHROMIUM_VERSION is the latest across all platforms (for display/reference).
# Use get_chromium_version() for the current platform's actual version.
# ---------------------------------------------------------------------------
-CHROMIUM_VERSION = "145.0.7632.159.8"
+CHROMIUM_VERSION = "145.0.7632.159.9"
PLATFORM_CHROMIUM_VERSIONS: dict[str, str] = {
- "linux-x64": "145.0.7632.159.8",
+ "linux-x64": "145.0.7632.159.9",
"linux-arm64": "145.0.7632.159.7",
"darwin-arm64": "145.0.7632.109.2",
"darwin-x64": "145.0.7632.109.2",
diff --git a/js/README.md b/js/README.md
index 8d2ca38..b410f98 100644
--- a/js/README.md
+++ b/js/README.md
@@ -11,7 +11,7 @@
Drop-in Playwright/Puppeteer replacement. Same API, same code — just swap the import. **3 lines of code, 30 seconds to unblock.**
-- **42 source-level C++ patches** — canvas, WebGL, audio, fonts, GPU, screen, automation signals
+- **48 source-level C++ patches** — canvas, WebGL, audio, fonts, GPU, screen, WebRTC, network timing, automation signals
- **0.9 reCAPTCHA v3 score** — human-level, server-verified
- **Passes Cloudflare Turnstile**, FingerprintJS, BrowserScan — tested against 30+ detection sites
- **`npm install cloakbrowser`** — binary auto-downloads, auto-updates, zero config
diff --git a/js/package.json b/js/package.json
index aeb81f3..08083e3 100644
--- a/js/package.json
+++ b/js/package.json
@@ -1,6 +1,6 @@
{
"name": "cloakbrowser",
- "version": "0.3.19",
+ "version": "0.3.20",
"description": "Stealth Chromium that passes every bot detection test. Drop-in Playwright/Puppeteer replacement with source-level fingerprint patches.",
"type": "module",
"main": "dist/index.js",
diff --git a/js/src/config.ts b/js/src/config.ts
index a72cbe2..eb3c90a 100644
--- a/js/src/config.ts
+++ b/js/src/config.ts
@@ -27,10 +27,10 @@ export { WRAPPER_VERSION };
// CHROMIUM_VERSION is the latest across all platforms (for display/reference).
// Use getChromiumVersion() for the current platform's actual version.
// ---------------------------------------------------------------------------
-export const CHROMIUM_VERSION = "145.0.7632.159.8";
+export const CHROMIUM_VERSION = "145.0.7632.159.9";
export const PLATFORM_CHROMIUM_VERSIONS: Record = {
- "linux-x64": "145.0.7632.159.8",
+ "linux-x64": "145.0.7632.159.9",
"linux-arm64": "145.0.7632.159.7",
"darwin-arm64": "145.0.7632.109.2",
"darwin-x64": "145.0.7632.109.2",