Get alerts on this situation
We’ll email you as it develops, and you can follow the whole thread from day one.
Unsubscribe anytime.
[SITUATION] · [ACTIVE]
2 clusters · 5 sources · 20 days · First seen · Last updated
Categories: TECHNOLOGY
Nebula Security July 2026 exploits
Entities: Mozilla · Nebula Security · Tor Browser
Overview
In early July 2026, Nebula Security announced a new Android root exploit chain, signalling a forthcoming series of high‑severity vulnerability disclosures.
Later that month, the firm detailed a separate but related bug affecting the Tor Browser. The vulnerability (CVE‑2026‑10702) resides in Firefox’s SpiderMonkey JIT engine and permits remote code execution when a malicious webpage is visited. Mozilla patched the flaw in Firefox 151.0.3 on 2 June 2026, and the Tor Project incorporated the fix into its latest releases. Nebula also demonstrated how this bug could be combined with a Linux kernel flaw (CVE‑2026‑43499, GhostLock) to escape sandboxes on ARM64 Android devices, expanding the impact of the original Android exploit chain. Users were urged to upgrade their browsers and Android systems promptly.
Timeline
-
3 days ago
[TECHNOLOGY] 5 sourcesTor Browser vulnerability enables remote code execution through malicious webpageA critical JIT bug in Firefox (CVE‑2026‑10702) lets a malicious webpage compromise Tor Browser; Mozilla patched it in June 2026 and Tor released updates. Nebula also showed a Linux kernel combo exploit, though未
-
22 days ago
[TECHNOLOGY] 3 sourcesNebula Security reveals Android 17 root exploit chainNebula Security disclosed 'IonStack', a proof‑of‑concept exploit that links a Firefox for Android bug with a 15‑year‑old Linux kernel flaw to gain root on Android 17 via a malicious link; both bugs are now pat
Sources
clubic.com · ilsoftware.it · invitehealth.substack.com · que.com · sf-encyclopedia.com