Skip to content
Personal Security · Privacy Tools

5 Best Privacy Browsers 2026: Brave vs Mullvad vs Firefox vs Tor

Brave, Mullvad Browser, hardened Firefox, Tor Browser and LibreWolf compared on tracker blocking, fingerprinting defence and extension support, after a year in which Chrome kept third-party cookies and killed the full uBlock Origin.

By ·Apr 11, 2026·Updated Sep 18, 2026·15 min·5 tools compared
Privacy BrowserBraveFirefoxTorPrivacy

Answer first

Use Brave if you want a browser that is private the moment you install it and that you will still be using in a month. Use Mullvad Browser if fingerprinting is your actual concern, because it applies the Tor Project's uniformity defences over an ordinary connection. Use Tor Browser when the fact that you visited a site is itself the risk, and use it only for those sessions. Use Firefox or LibreWolf if you want off Chromium entirely and still want the full uBlock Origin.

Two things changed in 2026, and both are structural

Chrome kept third-party cookies, permanently. Google delayed deprecation four times, then reversed the decision in July 2024. It confirmed in April 2025 that it would not deprecate them at all. In October 2025 it retired the Privacy Sandbox APIs that were supposed to replace them. Anyone who stayed on Chrome waiting for the privacy upgrade to arrive has been waiting for something that was cancelled. Safari, Firefox and Brave block third-party cookies today.

Chrome lost the full uBlock Origin. Manifest V2 extensions were disabled for regular Chrome users in July 2025. The last command-line workaround went in Chrome 150, and Chrome 151 stripped the remaining flags when it hit stable in July 2026. Manifest V2 extensions came off the Chrome Web Store at the end of August 2026. Chrome users now get uBlock Origin Lite, a deliberately reduced build. Firefox still supports both manifest versions. Brave was unaffected twice over: its Shields are compiled into Chromium rather than shipped as an extension, and Brave hosts four Manifest V2 extensions itself, including the full uBlock Origin.

Where "privacy focused" is marketing

Three questions separate architecture from positioning. Does the browser block third-party cookies and trackers by default, or only after you install something? Does it do anything at all about fingerprinting, which survives cookie clearing, private browsing and a VPN? And does the company's revenue depend on the thing the browser claims to block?

On that test, Arc has been removed from this comparison. It was a genuinely well-designed browser and it was never privacy-focused in architecture: no built-in ad blocker, minimal fingerprinting work, and a business model that was an open question throughout. It is now moot. Arc entered maintenance mode in 2025, The Browser Company was acquired by Atlassian for $610 million in a deal that closed in October 2025, and development moved to a different product called Dia. Arc still receives Chromium security patches and will receive no new features.

Brave passes the first two questions and has a real complication on the third, because it operates its own advertising network. This page names that rather than skipping it, and weighs it against what Brave has actually shipped: a rewritten adblock engine in January 2026, per-site data shredding on Android in April, GPU and WebGL fingerprinting defences in August, and email aliases in late August.

For the network layer rather than the browser layer, see the VPN comparison. A VPN and a privacy browser solve different problems, and neither substitutes for the other.

Quick Comparison

BrowserBest forEngineAd and tracker blockingFingerprinting approachExtensionsPrice
BraveA daily driver with strong defaults and no setupChromiumShields, built into the browser rather than an extensionRandomised per site and per session, plus GPU and WebGL de-identification added in version 1.93Full Chrome Web Store, and Brave still hosts four Manifest V2 extensions including the full uBlock OriginFree
Mullvad BrowserTor-grade fingerprint resistance without the Tor networkGecko (Firefox base)uBlock Origin preinstalled, telemetry strippedUniformity: every user looks identical, using the Tor Browser defencesFirefox Add-ons, though installing any changes your fingerprintFree
Firefox (hardened)Power users who want to make their own decisionsGeckoEnhanced Tracking Protection plus Total Cookie Protection by default, uBlock Origin available in fullresistFingerprinting, off by default, enabled by hand or via arkenfoxFull Firefox Add-ons, with Manifest V2 still supportedFree
Tor BrowserHiding the fact that you visited at allGecko (modified, Firefox ESR 140 base)Built-in NoScript and HTTPS-OnlyUniformity across all users, enforced by design including letterboxingDeliberately limited: adding extensions breaks the anonymity setFree
LibreWolfPre-hardened Firefox with nothing to configureGeckouBlock Origin preinstalledresistFingerprinting enabled by defaultFull Firefox Add-onsFree

Brave

Best for
A daily driver with strong defaults and no setup
Engine
Chromium
Ad and tracker blocking
Shields, built into the browser rather than an extension
Fingerprinting approach
Randomised per site and per session, plus GPU and WebGL de-identification added in version 1.93
Extensions
Full Chrome Web Store, and Brave still hosts four Manifest V2 extensions including the full uBlock Origin
Price
Free

Mullvad Browser

Best for
Tor-grade fingerprint resistance without the Tor network
Engine
Gecko (Firefox base)
Ad and tracker blocking
uBlock Origin preinstalled, telemetry stripped
Fingerprinting approach
Uniformity: every user looks identical, using the Tor Browser defences
Extensions
Firefox Add-ons, though installing any changes your fingerprint
Price
Free

Firefox (hardened)

Best for
Power users who want to make their own decisions
Engine
Gecko
Ad and tracker blocking
Enhanced Tracking Protection plus Total Cookie Protection by default, uBlock Origin available in full
Fingerprinting approach
resistFingerprinting, off by default, enabled by hand or via arkenfox
Extensions
Full Firefox Add-ons, with Manifest V2 still supported
Price
Free

Tor Browser

Best for
Hiding the fact that you visited at all
Engine
Gecko (modified, Firefox ESR 140 base)
Ad and tracker blocking
Built-in NoScript and HTTPS-Only
Fingerprinting approach
Uniformity across all users, enforced by design including letterboxing
Extensions
Deliberately limited: adding extensions breaks the anonymity set
Price
Free

LibreWolf

Best for
Pre-hardened Firefox with nothing to configure
Engine
Gecko
Ad and tracker blocking
uBlock Origin preinstalled
Fingerprinting approach
resistFingerprinting enabled by default
Extensions
Full Firefox Add-ons
Price
Free
1

Brave

Best Overall

Best for: The browser most people should actually use every day

“The only browser here that is both genuinely private out of the box and pleasant enough that people keep using it. Shields are compiled into the browser rather than bolted on as an extension, which is why Brave came through the Manifest V2 shutdown unaffected while Chrome users lost the full uBlock Origin. It has also shipped real fingerprinting work in 2026 rather than talking about it.”

Pros

  • Shields are patched into the Chromium source, so blocking does not depend on the extension platform and could not be removed by Google's Manifest V3 migration
  • Brave hosts four Manifest V2 extensions itself (uBlock Origin, AdGuard AdBlocker, NoScript, uMatrix) and exposes them under Settings, Extensions, Manifest V2 extensions, so the full uBlock Origin still runs here after Chrome removed it
  • Active fingerprinting work through 2026: version 1.93 de-identifies WebGL vendor and renderer strings and adds noise to the reported extension list, and version 1.81 blocks Microsoft Recall from screenshotting your browsing

Cons

  • Brave operates its own advertising network and rewards product, so the company's revenue comes from the thing the browser blocks, which is an uncomfortable structure even if the implementation is defensible
  • Randomised fingerprinting is a different bet from Tor-style uniformity: you become noisy rather than identical, which works against aggregation but does not make you anonymous
Honest Weakness: Brave asks you to accept that a company funded by advertising will keep making decisions against advertising's interest. The mechanism is at least coherent, since Brave Ads are opt-in and the targeting runs locally rather than on a server, but the incentive is structural and it has produced bad calls before. The other thing to be clear about: randomised fingerprinting makes you look like a different visitor each time, which frustrates cross-site correlation and does nothing to hide that you are a Brave user on a particular machine. If your threat model includes a determined adversary rather than an ad network, Brave is not the answer and Tor Browser is.

Why native Shields beat an extension in 2026

This stopped being a philosophical point and became a practical one. Google disabled Manifest V2 extensions for regular Chrome users in Chrome 138 in July 2025. Chrome 150 removed the last command-line escape and Chrome 151 stripped the remaining flags in July 2026. Manifest V2 extensions came off the Chrome Web Store at the end of August 2026. Chrome users are now on uBlock Origin Lite, a deliberately reduced Manifest V3 build. Brave Shields were never an extension: they are patches on the Chromium codebase, so none of that touched them. Brave additionally chose to keep hosting the full Manifest V2 uBlock Origin itself.

What Brave actually shipped in 2026

Reading a vendor's changelog is a better privacy test than reading its homepage. Brave's public privacy updates for 2026 list four shipped items. January: a rewritten Rust adblock engine that cut memory use by about 75 percent. April: per-site data shredding on Android. August: GPU and graphics-driver fingerprinting defences that de-identify WebGL vendor and renderer strings. Late August: email aliases, so you can sign up for services without handing over your real address. That is a shipping cadence, not a positioning statement.

The Chrome extension problem, honestly stated

Brave runs Chrome extensions, which is a large part of why people can switch to it. Every extension you install is also code with access to page content and a contribution to how identifiable you are. The privacy gain from switching to Brave is largely undone by installing six extensions from developers you have not evaluated. The discipline that actually matters is the same on every browser on this page: install as few extensions as you can live with, and prefer ones whose source you or someone you trust has read.

Free. Optional paid products (Brave VPN, Brave Leo premium) are separate from the browser.

Visit Brave
2

Mullvad Browser

Runner Up

Best for: Tor Browser's fingerprint resistance on the ordinary internet

“Built by Mullvad VPN in collaboration with the Tor Project, this is Tor Browser's anti-fingerprinting stack without the Tor network attached. Same hide-in-the-crowd design, same stripped telemetry, uBlock Origin preinstalled, and it connects over your normal connection or a VPN. It is the most under-known option here and the right answer more often than its profile suggests.”

Pros

  • Uses the Tor Browser fingerprinting defences, so spoofed fonts and timezone, letterboxed window dimensions and restricted canvas and WebGL readback make every user look alike rather than merely noisy
  • No Tor network means no exit-node latency and none of the broken-site behaviour that makes Tor Browser impractical as a daily driver
  • Telemetry and Firefox's data collection are removed rather than switched off, and uBlock Origin ships preinstalled

Cons

  • Uniformity only works if you leave it alone: installing extensions, resizing the window off its letterboxed steps or changing settings makes you more identifiable, not less
  • It is not anonymous. Your IP address is visible to every site unless you add a VPN, and the obvious VPN to add is the one sold by the company that makes the browser
Honest Weakness: Mullvad Browser exists partly to sell Mullvad VPN, and the product only reaches its full promise when paired with one. That is disclosed rather than hidden, and Mullvad's VPN has a better reputation than most, but the browser alone hides what you look like and not where you are. The second weakness is user-inflicted: this browser's entire defence is that you are indistinguishable from other users of it, and every customisation you make erodes that. If you are the sort of person who installs eight extensions and sets a custom font, you will get less out of this than out of Brave.

Uniformity versus randomisation

There are only two defensible answers to fingerprinting and this page contains both. Randomisation, which Brave uses, changes what you look like from site to site and session to session so that correlation fails. Uniformity, which Tor Browser and Mullvad Browser use, makes every user present the same values so that there is nothing to correlate. Uniformity is the stronger property and the more fragile one, because it depends on a large population of identically configured users and on you not changing anything. Randomisation is weaker and much harder to break by accident.

Who this is for

People who want to stop being followed around the web, who need sites to actually work, and who are not trying to hide from a state. That is a large group that usually ends up on Brave by default. Mullvad Browser is worth trying first if you are comfortable with a Firefox-shaped browser, because its fingerprinting posture is meaningfully stronger than Brave's and the daily-use cost, once uBlock Origin is already installed for you, is small.

The letterbox is not a bug

New users often try to fix the grey bars around the page. Those bars are the defence: window dimensions are one of the most identifying values a browser leaks, so the viewport is snapped to a small set of standard sizes shared by everyone. Maximising the window and dragging it to an unusual size hands that identifier straight back. If the letterboxing is intolerable, use Brave, where the privacy model does not depend on your window size.

Free. No account required. The Mullvad VPN it pairs with is a separate paid product.

Visit Mullvad Browser
3

Firefox (with hardening)

Best Open Source

Best for: Control, and the last mainstream engine that is not Chromium

“Firefox ships Enhanced Tracking Protection with Total Cookie Protection on by default for every user, and it still supports Manifest V2, which means the full uBlock Origin keeps working here after Chrome removed it. Out of the box it is a good browser. Hardened with arkenfox or an equivalent, it is close to the best. Left alone, it is well behind Brave, because resistFingerprinting is off by default.”

Pros

  • Total Cookie Protection is default worldwide, giving every site its own cookie jar so third parties cannot follow you across the web using shared cookies
  • Firefox continues to support both Manifest V2 and Manifest V3 extensions, so the full uBlock Origin remains available rather than the reduced Lite build Chrome users now get
  • It is the last widely used browser not built on Chromium, which matters for the web as a whole and not only for you

Cons

  • resistFingerprinting is not on by default and enabling it breaks sites, so the fingerprinting story out of the box is weaker than Brave's, Mullvad Browser's or LibreWolf's
  • Mozilla published a Terms of Use in February 2025 whose language read as a broad data grant, then rewrote it in March 2025 after sustained backlash, which cost trust it has not fully recovered
Honest Weakness: Default Firefox is not a privacy browser; it is a good browser with tracking protection. The gap between it and the hardened configuration people write about is real work: about:config edits, an arkenfox user.js you have to keep updated against each release, and accepting that some sites will break in ways you then have to debug. Most people who intend to harden Firefox never finish, and end up with a browser that is beaten out of the box by Brave, LibreWolf or Mullvad Browser. Then there is the trust question. The 2025 Terms of Use episode was a self-inflicted wound: the wording implied Mozilla was claiming rights over user data, Mozilla said that was never the intent and that its actual data use had not changed, and the terms were rewritten within days. Nothing technical changed. Confidence did.

Hardening, and knowing when to stop

The arkenfox user.js project is the reference hardening set. It disables telemetry, tightens referrer policy, restricts WebRTC leaks and can enable resistFingerprinting. The catch is maintenance: it tracks Firefox releases and needs re-checking when things break. If you are not going to maintain it, install LibreWolf instead, which is essentially this configuration shipped and maintained for you.

The extension advantage is now a real differentiator

Until 2025 this was a footnote. It is not any more. Chrome disabled Manifest V2 extensions for regular users in July 2025 and removed them from the Chrome Web Store at the end of August 2026, which means Chrome cannot run the full uBlock Origin and offers the reduced Manifest V3 Lite build instead. Firefox supports both manifest versions. If comprehensive content blocking matters to you and you do not want a Chromium browser, this is the reason to be on Firefox.

Private browsing is not privacy

Private windows stop Firefox writing history, cookies and form data to disk when you close them. They do not hide anything from the site, your network, your employer or your internet provider, and they do nothing about fingerprinting. Private browsing is for keeping things off a shared computer. Everything else on this page is for keeping things away from the other end of the connection.

4

Tor Browser

Best for Privacy

Best for: When the fact that you visited a site is the thing that must stay hidden

“Nothing else here is in the same category. Tor Browser routes traffic through three relays so no single point knows both who you are and what you are reading, and it enforces a uniform fingerprint so users are indistinguishable from each other. It is slow, some sites refuse it outright, and that is the correct trade for what it does. Current stable is 15.0.23, released 15 September 2026.”

Pros

  • Onion routing means the entry relay knows who you are but not where you are going, and the exit relay knows the destination but not who you are, which no VPN or browser setting can replicate
  • Every user presents the same fingerprint by design, including letterboxed window dimensions, so the anonymity set is the population of Tor Browser users
  • Maintained on a current base, with version 15.0 moving to Firefox ESR 140, adding vertical tabs on desktop and screen lock on Android, and the project now following Firefox's two-week release cadence

Cons

  • Slow by construction, and a large number of sites block or challenge Tor exit nodes, so it is not usable as a general-purpose browser
  • Any customisation, including maximising the window or installing an extension, damages the uniformity the entire model depends on
Honest Weakness: Tor Browser is a tool for a specific job, and using it for everything will make you worse off, not better. Logging into an account that identifies you over Tor discards the anonymity immediately, and the habit of leaving it running for ordinary browsing trains you to fight through broken sites and CAPTCHAs until you give up and switch back at the wrong moment. It is also not a panacea against a global adversary who can watch both ends of a connection. Use it deliberately, for the sessions that need it, with nothing about that session linked to your identity, and use something else for the rest of your life.

What onion routing actually protects

Traffic is wrapped in three layers of encryption and passed through three relays. The entry relay sees your IP address and the next relay, but not your destination. The middle relay sees only two relays. The exit relay sees the destination but not you. The property this gives you is that no single observer holds both halves. A VPN, by contrast, moves complete knowledge of both halves from your internet provider to the VPN company. That is a genuine improvement in many situations and it is not the same thing.

Fingerprint uniformity, enforced

Every Tor Browser presents the same user agent, the same timezone, the same font set and a letterboxed viewport snapped to standard sizes. The point is that there is nothing in your browser to distinguish you from every other Tor Browser user. This is why the project pushes back on customisation requests that would be reasonable in any other browser: a unique configuration is a unique user.

Where the threat model breaks

Tor protects the network layer. It cannot protect you from what you do inside the session. Logging into an account tied to your name, uploading a document with your metadata in it, or maintaining a distinctive writing style all defeat it above the protocol. It also gives no protection against an adversary with visibility at both ends of the circuit. Treat it as a strong network-layer control inside a wider set of practices, not as a switch that makes you anonymous.

5

LibreWolf

Honorable Mention

Best for: Hardened Firefox with none of the maintenance

“An independent Firefox build with telemetry and data collection removed rather than disabled, uBlock Origin preinstalled, and resistFingerprinting on by default. It is what most people mean when they say they are going to harden Firefox, except that it is already done and somebody else keeps it current. The cost is a smaller project with a slower path to Firefox's security fixes.”

Pros

  • Telemetry, experiments, Pocket, sponsored content and data collection are removed from the build, not toggled off in a settings page you can accidentally undo
  • uBlock Origin ships preinstalled and resistFingerprinting is enabled by default, so the out-of-box posture is far ahead of stock Firefox
  • Available on Windows, macOS, Linux across most major distributions, and OpenBSD, which is wider platform coverage than most hardened forks manage

Cons

  • Security updates arrive downstream of Firefox stable rather than with it, which is a real exposure window on a browser
  • resistFingerprinting on by default breaks some sites, and the workarounds people apply to unbreak them quietly reduce the protection they installed it for
Honest Weakness: Two things. First, LibreWolf is built from Firefox stable source by a small volunteer project, so a Firefox security release reaches you later than it reaches Firefox users, and for a browser that gap is the thing that matters most. Second, the default-on resistFingerprinting is both the main reason to use LibreWolf and the main reason people stop: sites misbehave, users disable it for that site, then for another, and eventually they are running a Firefox fork with the distinguishing feature switched off. If you are going to do that, run Mullvad Browser instead, where the same protections come with a larger and more uniform user population behind them.

What it removes, precisely

LibreWolf describes itself as an independent fork whose goals are privacy, security and user freedom. In practice it strips Mozilla's telemetry, studies and data collection from the build, ships with a content blocker already installed, and applies a set of privacy-oriented settings and patches on top of Firefox stable. Nothing here is secret or clever; it is the configuration privacy guides recommend, applied at build time so it cannot drift.

LibreWolf or Mullvad Browser

They are close relatives solving the same problem in different ways. LibreWolf is a hardened general-purpose Firefox you can live in, with your own settings and extensions. Mullvad Browser optimises for fingerprint uniformity and asks you not to change anything. If you want a normal browser with the privacy work already done, take LibreWolf. If you specifically want to be indistinguishable from other users, take Mullvad Browser and leave it alone.

Free, open source

Visit LibreWolf

Which One Should You Pick?

Use CaseOur Recommendation
Everyday browsing, strong defaults, zero configurationBrave. Shields block ads and trackers without an extension, they survived the Manifest V2 shutdown because they were never an extension, and Brave still hosts the full uBlock Origin for people who want it on top. If you want the same thing on a non-Chromium engine, LibreWolf is the closest equivalent.
Stop cross-site fingerprinting without losing usable sitesMullvad Browser. It applies Tor Browser's uniformity defences over an ordinary connection, ships uBlock Origin preinstalled, and has none of the latency or blocked-site problems of the Tor network. Leave the window letterboxed and install nothing.
Anonymous research or communication where being seen at all is the riskTor Browser, current stable 15.0.23. Use it only for that session, log into nothing that identifies you, install no extensions, and do not maximise the window. Use a different browser for everything else.
You want comprehensive content blocking and refuse to use ChromiumFirefox, which still supports Manifest V2 and therefore the full uBlock Origin, rather than the reduced Manifest V3 Lite build Chrome users are now limited to. Harden it with arkenfox if you will maintain it, and use LibreWolf if you will not.
You are on Chrome and were waiting for third-party cookies to go awayStop waiting and switch. Google abandoned third-party cookie deprecation in April 2025 and retired the Privacy Sandbox replacement APIs in October 2025, so Chrome's third-party cookies work exactly as they always did. Brave, Firefox and Safari all block them today.
You used Arc and need somewhere to goArc went into maintenance mode in 2025 and The Browser Company was acquired by Atlassian, with development moved to Dia. It still gets Chromium security patches and gets no new features. Brave is the closest Chromium daily driver with a real privacy architecture; Firefox or LibreWolf if you want off Chromium entirely.

How we evaluated

Every claim on this page was checked against the vendor's or project's own material on 18 September 2026: release notes, privacy changelogs, project documentation and the browsers' own feature pages. No capability is taken from another comparison.

Browsers were assessed on five criteria, weighted in this order:

  1. Default behaviour. What the browser does before you configure anything. Most people never open a settings page, so a protection that requires configuration protects almost nobody.
  2. Where the protection lives. Whether blocking is implemented in the browser itself or delegated to an extension. 2026 turned this from a design preference into the difference between keeping full content blocking and losing it.
  3. Fingerprinting posture. Whether the browser randomises what it reports, enforces uniformity across its users, blocks known fingerprinting scripts, or does none of the above. Cookie blocking alone is no longer a meaningful claim.
  4. Shipping record. What the project actually released in the last twelve months, read from its own changelog. A privacy homepage costs nothing to write; a release cadence does not.
  5. Incentive structure. Who pays for the browser, and whether that conflicts with what it claims to do.

What was checked, and where

  • Brave: the Brave privacy updates log for the 2026 releases (adblock engine rewrite, Android Shred, GPU and graphics-driver fingerprinting defences in version 1.93, email aliases in 1.94, Microsoft Recall blocking in 1.81), and Brave's published position on hosting Manifest V2 extensions.
  • Mullvad Browser: the Mullvad Browser page and the Tor Project's announcement of the joint development, for the shared fingerprinting defences, stripped telemetry and preinstalled uBlock Origin.
  • Firefox: Mozilla's documentation for Total Cookie Protection and Enhanced Tracking Protection defaults, Mozilla's continued support for both Manifest V2 and V3, and the public record of the February 2025 Terms of Use and its March 2025 rewrite.
  • Tor Browser: the Tor Project blog for the current stable release (15.0.23, 15 September 2026), the 15.0 move to Firefox ESR 140, and the shift to a two-week release cadence.
  • LibreWolf: the project site for removed telemetry, preinstalled uBlock Origin, default resistFingerprinting and platform coverage.
  • Chrome and Safari are not ranked here but are the baseline everything is measured against. Chrome's third-party cookie reversal, Privacy Sandbox retirement and Manifest V2 timeline were checked against Google's own announcements. Safari 26's fingerprinting work was checked against the WebKit release documentation.

What we did not do

No hands-on benchmarking or test-suite scoring. These browsers were not run through a fingerprinting test harness for this page. Assessments rest on documented architecture, vendor changelogs and project release notes, and each entry says which of those it rests on.

No ranking on speed or interface. All five are fast enough on modern hardware, and the differences that matter here are architectural.

One point of genuine uncertainty: Safari 26 clearly blocks known fingerprinting scripts from reaching device-characteristic APIs and from writing long-lived storage, per Apple's own WebKit documentation. Reporting disagrees on whether Link Tracking Protection is enabled by default outside Private Browsing. This page does not resolve that, and if it matters to you, check the setting on your own device rather than trusting either account.

Note

Editorial independence: this is a vendor-neutral comparison with no paid placements, sponsorships or affiliate links. Rankings reflect fit for the stated use cases, not commercial relationships.

Last verified: 18 September 2026. Vendor privacy changelogs, release notes, extension-platform status, default protection settings and ownership changes were all rechecked on this date. Arc was removed in this revision following its move to maintenance mode and the Atlassian acquisition of The Browser Company.

Frequently Asked Questions

Did Chrome ever get rid of third-party cookies?
No, and the plan is formally dead. Google delayed third-party cookie deprecation from 2022 to 2023 to 2024 to 2025, reversed the decision in July 2024, and confirmed in April 2025 that it would not deprecate them at all. In October 2025 it went further and retired the Privacy Sandbox APIs that were supposed to replace them, including Topics, Protected Audience and Attribution Reporting. The practical result for a Chrome user in 2026 is that third-party cookies behave exactly as they did in 2019. Safari, Firefox and Brave all block them by default. If cookie-based cross-site tracking is the thing you want stopped, changing browser is the only thing that stops it.
What happened to uBlock Origin on Chrome, and does it affect Brave?
Chrome's Manifest V3 migration removed it. Chrome 138 disabled Manifest V2 extensions for regular users in July 2025. Chrome 150 removed the last command-line workaround. Chrome 151 stripped the remaining flags when it reached stable in July 2026, and Manifest V2 extensions were pulled from the Chrome Web Store at the end of August 2026. Chrome users get uBlock Origin Lite, a Manifest V3 build with reduced filtering capability. Brave is unaffected twice over. Shields are patched into the Chromium source rather than implemented as an extension. Separately, Brave chose to keep hosting four Manifest V2 extensions itself (uBlock Origin, AdGuard AdBlocker, NoScript and uMatrix), which you enable under Settings, Extensions, Manifest V2 extensions. Firefox also still supports both manifest versions.
What is browser fingerprinting, and why does a VPN not stop it?
Fingerprinting builds an identifier out of what your browser reveals about your machine: screen and window dimensions, installed fonts, timezone, language, GPU and WebGL renderer strings, audio processing quirks, hardware concurrency and dozens of smaller values. Combined, those are often unique to one device, and none of them are cookies, so clearing cookies and using private browsing changes nothing. A VPN changes your IP address, which is one value in a set of dozens, so a fingerprint survives it intact. The only real defences are randomising what you report (Brave, which added GPU and WebGL de-identification in 2026) or making everyone report the same thing (Tor Browser and Mullvad Browser). Safari 26 added a third variant: blocking known fingerprinting scripts from reaching the relevant APIs at all.
Which browsers are privacy focused as marketing rather than as architecture?
The test is whether the privacy behaviour is in the code or in the copy. Ask three questions. Does it block third-party cookies and trackers by default, or only after you install something? Does it do anything at all about fingerprinting, or does it stop at cookies? And does the company's revenue depend on the thing the browser claims to block? Chrome fails the first two. Arc was a well-designed browser that was never privacy-focused in architecture and is now in maintenance mode under Atlassian after The Browser Company was acquired, with development moved to Dia. Brave passes the first two and has an honest complication on the third, since it runs its own advertising network, which is why this page names it rather than glossing over it. Safari passes on cookies and, from Safari 26, does substantial work against known fingerprinting scripts, but it is available on Apple platforms only.
Does private browsing or incognito mode make me private?
No. Private windows stop the browser writing history, cookies, cache and form data to your disk for that session. That is protection against another person using the same computer, and nothing more. The site still sees your IP address, can still fingerprint you, and can still recognise you if you log in. Your employer, your network administrator, your internet provider and the destination site all see the same traffic they would have seen anyway. If the goal is to keep something off a shared machine, private browsing is the right tool. If the goal is to not be tracked or identified, it does nothing and you need a browser on this page.
Is Brave trustworthy given that it runs an ad network?
It is a fair question and the answer is a qualified yes, with the qualification stated rather than buried. Brave Ads are opt-in through Brave Rewards, and the matching happens on your device rather than on a server, so the browser is not shipping a behavioural profile to Brave. Shields block third-party ads and trackers by default whether or not you ever enable Rewards. The structural concern remains: a company whose revenue comes from advertising is making the decisions about what advertising gets blocked, and Brave has made calls in the past that drew justified criticism. Weigh that against what it has actually shipped, which in 2026 alone includes a rewritten adblock engine, GPU and WebGL fingerprinting defences, Microsoft Recall blocking and email aliases. If the incentive structure is disqualifying for you, Mullvad Browser and LibreWolf have no advertising business at all.

About the author

is the founder and creator of LoginRadius, a customer identity platform he built and scaled to over a billion users. He is now the founder of GrackerAI, a GEO platform for B2B SaaS and cybersecurity teams, and has spent more than 15 years building identity and security products.

Related Comparisons