Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser
Exploitation reportFirefoxTor BrowserOur summary
Researchers from Nebula Security revealed that a malicious webpage visit alone could exploit a recently patched vulnerability in Firefox, which also impacted Tor Browser. Tracked as CVE-2026-10702, the flaw allows arbitrary code execution within the browser’s renderer process and was rated High by Mozilla. It was addressed in the Firefox 151.0.3 update. The vulnerability stems from an incorrect classification of a JavaScript operation during just-in-time compilation, leading to potential memory corruption. Public exploit code has been shared, demonstrating how this flaw can serve as the initial stage in a broader exploitation chain targeting Android devices. Users are advised to update their browsers immediately to mitigate risk.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.