Close Menu
    What's Hot

    Trying to Make a Buck Off a Data Center, One 6-Pack at a Time

    Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser

    Record Numbers of FOIA Public Document Requests Are in Limbo or Unfulfilled

    Facebook X (Twitter) Instagram
    Trending
    • Trying to Make a Buck Off a Data Center, One 6-Pack at a Time
    • Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser
    • Record Numbers of FOIA Public Document Requests Are in Limbo or Unfulfilled
    • Hezbollah Attacks Strategic Area in Southern Lebanon, Israel Says
    • St. Mary’s, Newfoundland, Will No Longer Reek of Rotten Fish Sauce
    • Hollywood Foreign Press Association Sues Over Takeover of Golden Globes
    • Houlihan Lokey, Inc. (HLI) Q1 2027 Earnings Call Transcript
    • Jack Grealish transfer: Man City forward attracting interest from Saudi side Al Hilal after pre-season snub – Paper Talk | Football News
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser

    adminBy adminJuly 30, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalJul 29, 2026Vulnerability / Browser Security

    Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser

    Nebula Security says a patched Firefox JIT flaw could be triggered by simply visiting a malicious webpage and was also used to compromise Tor Browser.

    Tracked as CVE-2026-10702, the bug provides arbitrary code execution inside the browser’s renderer process. Mozilla rated it High and fixed it in the Firefox 151.0.3 update.

    “No settings or additional user interaction are required,” Eten Zou, CEO of Nebula Security, told The Hacker News. “Visiting a malicious webpage is enough to trigger it,” Zou said every Tor Browser release that incorporated a vulnerable Firefox version was affected, though researchers have not identified the exact Tor releases.

    On its own, the bug runs code only inside Firefox’s sandboxed content process. Nebula released public exploit material and used the flaw as the first stage of IonStack, a browser-to-kernel chain built for an ARM64 device running Android 17. The released end-to-end code targets one supported Google build, although Zou said the browser flaw itself is not ARM-specific.

    The public code contains Firefox 151.0 offsets for the supported ARM64 Android 17 build. Zou said each exploitation step is architecture-independent and described the x86 path as more stable, although Nebula has not completed the full chain for that architecture.

    Cybersecurity

    Firefox users should update to the latest release. The Hacker News traced the faulty alias declaration through Mozilla’s source history to Bug 1995077, which landed for Firefox 147. The override is present in Firefox 151.0.2 and absent from Firefox 151.0.3. That places the affected stable-release range at Firefox 147 through 151.0.2.

    Mozilla’s advisory does not list Firefox ESR, and the faulty override is absent from Firefox ESR 140.12. As of July 28, 2026, the available primary-source record does not establish exploitation against users in the wild.

    In its technical analysis, Nebula traces the issue to MObjectToIterator when it runs with skipRegistration set to true. Firefox’s just-in-time (JIT) compiler turns frequently run JavaScript into native machine code, and to do that safely it has to track which operations can touch memory.

    Firefox treated the operation as a read even though resolving a lazy property can allocate a replacement dynamic-slots buffer and free the old one.

    Global value numbering then treated a later slots-buffer load as redundant and reused the earlier pointer after it had become stale. Nebula’s released exploit reclaims the freed allocation, leaks a hidden-class pointer, builds a fake object, and corrupts a Uint8Array to gain arbitrary memory read and write. The Android code then changes memory protections and redirects a WebAssembly function entry point to ARM64 shellcode.

    The failure turns on a narrow compiler contract: an operation capable of replacing the object’s dynamic-slots buffer was labelled as a read. That incorrect contract let otherwise valid optimisation logic preserve a pointer the runtime had already invalidated.

    Cybersecurity

    Mozilla’s source-level fix removes the custom read-only alias handling from ObjectToIterator and adjusts the related iterator operation. That prevents the optimiser from treating a mutation-capable step as a harmless load and retaining the stale pointer.

    IonStack’s second stage is CVE-2026-43499, a separate Linux kernel futex flaw that Nebula calls GhostLock. CVE-2026-10702 provides the remote browser foothold; CVE-2026-43499 carries it to root on the supported Android build.

    Zou said GhostLock is invoked directly from Firefox. He added that Android’s weaker sandbox makes exploitation easier, but Nebula does not believe a stronger desktop sandbox would prevent the attack.

    Updating Firefox blocks the documented browser entry point, but it does not patch GhostLock itself.

    Browser Compromise malicious Researchers show Single Tor visit Webpage
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleRecord Numbers of FOIA Public Document Requests Are in Limbo or Unfulfilled
    Next Article Trying to Make a Buck Off a Data Center, One 6-Pack at a Time
    admin
    • Website

    Related Posts

    Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments

    July 29, 2026

    Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

    July 29, 2026

    Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads

    July 29, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    Trying to Make a Buck Off a Data Center, One 6-Pack at a Time

    Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser

    Record Numbers of FOIA Public Document Requests Are in Limbo or Unfulfilled

    Hezbollah Attacks Strategic Area in Southern Lebanon, Israel Says

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by