Desktop browser / in development

Where the engine becomes a browser.

Galileo Browser is the desktop product being built on Galileo Engine. The shell, profiles, privacy controls, media, extensions, and developer tools are taking shape, but compatibility, security, packaging, and release readiness are not yet qualified. There is no public release today.

Galileo Browser symbol

The product boundary

A browser is more than a rendering engine.

Galileo Browser is the product layer: windows, tabs, navigation, profiles, privacy controls, settings, media, permissions, extensions, and eventually the infrastructure required to ship and maintain a release. It is being built on Galileo Engine, which derives from Servo, the Rust engine started by Mozilla Research in 2012.

Some of those surfaces already work in development. Others remain partial or unqualified. A page rendering is not the same as a usable browser, and a usable browser is not automatically a secure release.

Current work

The shell is becoming a product.

Public project updates show partial work across these surfaces. The status stays conservative while focused testing and wider qualification catch up.

01 / foundation

Pages, navigation, and browser state.

Rendering, URL and network work, tabs, browser chrome, profiles, private browsing, history, bookmarks, downloads, permissions, and session restore exist at different stages of development.

02 / hard cases

Media, blocking, and devtools.

Retained evidence covers GStreamer and Media Source Extensions work, native request blocking, WebDriver, developer tooling, and the August Turnstile canary across all three test modes.

03 / extensions

Compatibility with a safety boundary.

Reviewed packages, permission review, content scripts, storage, request blocking, and a browser-owned Manifest V2 runtime already exist — without inheriting Google's extension limits or claiming broad Chrome or Firefox parity.

Extensions are part of the browser

Manifest V2, Chrome, Firefox, and Galileo.

Galileo already runs reviewed Manifest V2 background pages together with content scripts, storage, messaging, permissions, network interception, and browser-owned extension surfaces. These are active parts of the browser, not only a plan.

Galileo does not inherit Google's current extension restrictions. Familiar Chrome and Firefox API shapes are supported selectively, while privileged decisions stay in the browser and Galileo's own extension path remains under our control.

Read the extension roadmap ↗
Manifest V2runtime activeReviewed background pages, browser actions, content scripts, storage, messaging, and permission-gated scripting paths run through browser-owned hosts.
Chrome + Firefox API shapesselective compatibilityFamiliar APIs are implemented where they serve the browser, while unsupported methods remain explicit rather than being silently accepted.
Galileo extension pathbrowser-ownedDeterministic packages, fixed digests, explicit permission review, and disabled-by-default installation remain under Galileo's control.
uBlock Origincompatibility previewThe reviewed package exercises the real runtime. Full isolated-DOM behaviour, response filtering, and automatic updates are not yet qualified.

Official catalog / pre-alpha

Three reviewed packages.

The catalog is published from GalileoExtensions. Packages remain disabled until their permissions are reviewed and they are explicitly enabled.

01 / reviewed preview

Galileo Tracker Shield

A transparent starter blocker using reviewed static network rules and browser-parsed content CSS.

Not yet: background scripts, dynamic or session rules, and automatic updates.
02 / Android preview

Galileo Haptic Feedback

Bounded link, control, and deliberate-scroll vibration cues through navigator.vibrate() and local extension storage.

Android only; it safely does nothing on desktop or unsupported devices.
03 / compatibility preview

uBlock Origin 1.73.0

A reviewed runtime package for exercising Galileo's Manifest V2 and browser-owned extension APIs.

Not yet: full isolated-DOM behaviour, response-filter streaming, or automatic updates. Icon: uBlock Origin (MPL-2.0, © gorhill).

Privacy by architecture

Your browser, your data.

Galileo is being designed local first. Using the browser should not require a Galileo account, and planned sync should connect a person's own devices rather than make a company account the centre of the product.

01 / local first

No account required to use a browser.

Profiles are designed to live on the user's machine. The vault work defines PIN or password protection around sensitive profile state, with offline-first operation as the default.

02 / locked vaults

Locks you can hold.

The tested vault contract denies sensitive access while a profile is locked and keeps key material out of export/import. Production encryption of profile data remains further work.

03 / device-to-device

Encrypted sync without a central account.

The envelope format and conflict rules exist for planned device-to-device sync. The transport is still being built, so Galileo does not claim production sync today.

No public release

What “almost working” still leaves open.

We want a browser people can use and trust, so the missing work stays on the page.

Works in development

Development builds open pages, expose browser chrome, exercise focused real-site and standards probes, run selected media paths, and carry a growing set of browser-owned product services.

Still needs proof

Broad compatibility, process isolation, security response, startup speed, memory budgets, cross-platform packaging, signed updates, recovery, accessibility, and a supportable release channel.

A deliberate fork

Contribute back while Galileo grows.

When Galileo's code is useful to Servo and fits its contribution policy, we intend to offer it back for review — tested and marked as AI-assisted where appropriate. Upstream maintainers decide what belongs in their project.

As Galileo-owned browser services and engine work expand, the boundary may become large enough for Galileo Engine to stand more independently. That is a long-term direction, not the project's current state.

Next

Follow the browser as it earns its name.

Follow the project on GitHub