CVE Tools

Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser

The Hacker NewsBy The Hacker News

Exploitation reportFirefoxTor Browser

Our summary

Researchers from Nebula Security revealed that a malicious webpage visit alone could exploit a recently patched vulnerability in Firefox, which also impacted Tor Browser. Tracked as CVE-2026-10702, the flaw allows arbitrary code execution within the browser’s renderer process and was rated High by Mozilla. It was addressed in the Firefox 151.0.3 update. The vulnerability stems from an incorrect classification of a JavaScript operation during just-in-time compilation, leading to potential memory corruption. Public exploit code has been shared, demonstrating how this flaw can serve as the initial stage in a broader exploitation chain targeting Android devices. Users are advised to update their browsers immediately to mitigate risk.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store