Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser
Overview
Researchers at Nebula Security have discovered a serious vulnerability in the Tor Browser, linked to a flaw in Firefox's Just-In-Time (JIT) compiler. This vulnerability, identified as CVE-2026-10702, allows attackers to execute arbitrary code within the browser's renderer process simply by having a user visit a malicious webpage. Mozilla has classified this issue as high severity and has released a patch in Firefox version 151.0.3 to address the flaw. Since the Tor Browser is built on Firefox, users of Tor are particularly at risk, as no special settings or actions are needed from them to be compromised. This situation raises significant concerns about the security of users relying on the Tor network for privacy and anonymity online.
Key Takeaways
- Affected Systems: Affected products include Tor Browser and Firefox versions prior to 151.0.3. The vulnerability arises from a flaw in the Firefox JIT compiler.
- Action Required: Mozilla has released a patch in Firefox version 151.
- Timeline: Newly disclosed
Original Article Summary
Nebula Security says a patched Firefox JIT flaw could be triggered by simply visiting a malicious webpage and was also used to compromise Tor Browser. Tracked as CVE-2026-10702, the bug provides arbitrary code execution inside the browser's renderer process. Mozilla rated it High and fixed it in the Firefox 151.0.3 update. "No settings or additional user interaction are required," Eten Zou,
Impact
Affected products include Tor Browser and Firefox versions prior to 151.0.3. The vulnerability arises from a flaw in the Firefox JIT compiler.
Exploitation Status
The exploitation status is currently unknown. Monitor vendor advisories and security bulletins for updates.
Timeline
Newly disclosed
Remediation
Mozilla has released a patch in Firefox version 151.0.3. Users are advised to update to this version to mitigate the vulnerability.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to CVE, Vulnerability, Patch, and 1 more.