Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser

Summary

Researchers at Nebula Security have demonstrated that a previously patched Firefox Just-In-Time (JIT) compiler flaw, tracked as CVE-2026-10702, can be exploited by merely visiting a malicious webpage. This vulnerability allows for arbitrary code execution within the browser's renderer process and has been confirmed to impact the Tor Browser.

IFF Assessment

FOE

This vulnerability allows for arbitrary code execution within the browser's renderer process, posing a direct threat to users' security and privacy.

Severity

4.3 Medium

The vulnerability allows for arbitrary code execution via a simple webpage visit, indicating a high attack vector. The impact includes potential compromise of user data and system control, rated as High.

Defender Context

This finding highlights the persistent risk of even patched vulnerabilities if not diligently applied to all downstream projects, such as Tor Browser. Defenders should prioritize rapid patching and consider proactive measures against JIT compiler exploits.

Read Full Story →