< Back to situations

We’ll email you as it develops, and you can follow the whole thread from day one.

[SITUATION] · [ACTIVE]

2 clusters · 5 sources · 20 days · First seen · Last updated

Categories: TECHNOLOGY

Nebula Security July 2026 exploits

Entities: Mozilla · Nebula Security · Tor Browser

Overview

In early July 2026, Nebula Security announced a new Android root exploit chain, signalling a forthcoming series of high‑severity vulnerability disclosures.

Later that month, the firm detailed a separate but related bug affecting the Tor Browser. The vulnerability (CVE‑2026‑10702) resides in Firefox’s SpiderMonkey JIT engine and permits remote code execution when a malicious webpage is visited. Mozilla patched the flaw in Firefox 151.0.3 on 2 June 2026, and the Tor Project incorporated the fix into its latest releases. Nebula also demonstrated how this bug could be combined with a Linux kernel flaw (CVE‑2026‑43499, GhostLock) to escape sandboxes on ARM64 Android devices, expanding the impact of the original Android exploit chain. Users were urged to upgrade their browsers and Android systems promptly.

Timeline

  1. 3 days ago

    [TECHNOLOGY] 5 sources
    Tor Browser vulnerability enables remote code execution through malicious webpage

    A critical JIT bug in Firefox (CVE‑2026‑10702) lets a malicious webpage compromise Tor Browser; Mozilla patched it in June 2026 and Tor released updates. Nebula also showed a Linux kernel combo exploit, though未

  2. 22 days ago

    [TECHNOLOGY] 3 sources
    Nebula Security reveals Android 17 root exploit chain

    Nebula Security disclosed 'IonStack', a proof‑of‑concept exploit that links a Firefox for Android bug with a 15‑year‑old Linux kernel flaw to gain root on Android 17 via a malicious link; both bugs are now pat­

Sources

clubic.com · ilsoftware.it · invitehealth.substack.com · que.com · sf-encyclopedia.com