< Back to all clusters
[TECHNOLOGY] · 5 sources

Tor Browser vulnerability enables remote code execution through malicious webpage

Researchers at Nebula Security disclosed a high‑severity vulnerability (CVE‑2026‑10702) in Firefox’s SpiderMonkey JIT engine that allows arbitrary code execution when a malicious webpage is rendered. Because Tor Browser is built on Firefox, the flaw can be exploited to compromise Tor users without any interaction beyond visiting the page. The attack chain involves a use‑after‑free error during JIT optimization, which can be leveraged to gain arbitrary read/write access in the browser’s renderer process.

Mozilla patched the bug in Firefox 151.0.3 on June 2, 2026, and the Tor Project incorporated the fix into updated Tor Browser releases. Nebula also demonstrated a further exploit combining this bug with a Linux kernel vulnerability (CVE‑2026‑43499, GhostLock) to escape the sandbox on ARM64 Android devices, but no real‑world exploitation has been reported. Users are advised to update to the latest Firefox and Tor Browser versions.

Entities: Mozilla · Nebula Security · Tor Browser