As cited
Copy frozen at (site build).
vulnerabilities
Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser
Researchers at Nebula Security demonstrated that a patched Firefox JIT compiler flaw (CVE-2026-10702) could be exploited to achieve arbitrary code execution in the browser's renderer process with no user interaction beyond visiting a malicious webpage. The vulnerability, which Mozilla rated High severity, was also successfully used to compromise Tor Browser and was addressed in Firefox 151.0.3.
Why it matters: All Firefox and Tor Browser users need to update immediately, as the vulnerability requires no user interaction beyond a website visit and provides direct code execution inside the browser process.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser
Researchers at Nebula Security demonstrated that a patched Firefox JIT compiler flaw (CVE-2026-10702) could be exploited to achieve arbitrary code execution in the browser's renderer process with no user interaction beyond visiting a malicious webpage. The vulnerability, which Mozilla rated High severity, was also successfully used to compromise Tor Browser and was addressed in Firefox 151.0.3.
Why it matters: All Firefox and Tor Browser users need to update immediately, as the vulnerability requires no user interaction beyond a website visit and provides direct code execution inside the browser process.
- Source published
- First seen by Cybersecurity Tracker