Security · 1h ago
Single Malicious Page Can Compromise Tor Browser via Firefox Flaw
Researchers at Nebula Security demonstrated that a patched Firefox JIT vulnerability, CVE-2026-10702, can be triggered by visiting a malicious webpage, compromising Tor Browser. The bug enables arbitrary code execution in the browser's renderer process without user interaction. Mozilla rated it High and fixed it in Firefox 151.0.3.
Meridian48 take
The attack's simplicity—no clicks or settings changes—underscores how even privacy-focused tools like Tor remain vulnerable to browser engine flaws.
Read the full reporting
Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser →
The Hacker News
tor-browserfirefox-vulnerability