← BACK TO FEED
TAG

tor browser1 articles

One Webpage Visit Was Enough to Own Your Browser — and Then Your Kernel

Researchers at Nebula Security have disclosed a patched Firefox vulnerability (CVE-2026-10702) that allowed arbitrary code execution simply by visiting a malicious webpage, with no additional user interaction required. The flaw, stemming from a JIT compiler error that incorrectly treated a memory-mutating operation as a safe read, affected Firefox versions 147 through 151.0.2 and also impacted Tor Browser builds using vulnerable Firefox versions. Nebula chained the browser exploit with a separate Linux kernel flaw (CVE-2026-43499) to achieve full device compromise on ARM64 Android devices, though updating to Firefox 151.0.3 blocks the browser entry point.

30 Jul 2026