← Back to Feed

Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser

CVE-2026-10702

July 29, 2026 · The Hacker News · Severity: HIGH

Nebula Security disclosed CVE-2026-10702, a patched Firefox JIT flaw (rated High) that allows arbitrary code execution inside the browser's renderer process by simply visiting a malicious webpage. No settings or additional user interaction is required beyond the page visit. Mozilla fixed it in Firefox 151.0.3. The flaw also affects Tor Browser releases using vulnerable Firefox versions. Nebula released public exploit material and used the bug as the first stage of IonStack, a browser-to-kernel chain built for Android 17 on ARM64, though the browser flaw itself is not ARM-specific.

Key Takeaways

  • CVE-2026-10702 is a Firefox JIT flaw exploitable by simply visiting a malicious webpage, requiring no additional user interaction, affecting Tor Browser as well.
  • Mozilla patched the vulnerability in Firefox 151.0.3; users should update immediately, especially Tor Browser users who may be on delayed update cycles.
  • The bug provides renderer-level code execution and was publicly demonstrated as the first stage of a full browser-to-kernel exploit chain on Android.
☕ Buy a Coffee