{"id":2083,"date":"2026-07-29T14:08:41","date_gmt":"2026-07-29T14:08:41","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2083"},"modified":"2026-07-29T14:08:41","modified_gmt":"2026-07-29T14:08:41","slug":"researchers-show-a-single-malicious-webpage-visit-can-compromise-tor-browser","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2083","title":{"rendered":"Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Swati Khandelwal<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Jul 29, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Browser Security<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiOwFIxqT8kRBNj9LdZBZhO1g2RPJwUttxQosrS_mPoNXkIR-JB-yM87HPzuPZ1tazourGhRg9Sco6YQEGZkC77DSqXBYjp0DkNDAUHOaAOnIisRYNPAQfNWwqnmoILXOgR0wwyGVNlU3kSVRU6TcfyAx5ztaAWZfbKnCDJYgUeIVsM7n7O2zq7fGc-xnI\/s1700-e365\/tor-exploit.gif\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Nebula Security says a patched Firefox JIT flaw could be triggered by simply visiting a malicious webpage and was also used to compromise Tor Browser.<\/p>\n<p>Tracked as <strong>CVE-2026-10702<\/strong>, the bug provides arbitrary code execution inside the browser&#8217;s renderer process. Mozilla rated it High and fixed it in the <a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-54\/\" target=\"_blank\">Firefox 151.0.3 update<\/a>.<\/p>\n<p>\u00abNo settings or additional user interaction are required,\u00bb Eten Zou, CEO of Nebula Security, told The Hacker News. \u00abVisiting a malicious webpage is enough to trigger it,\u00bb Zou said every Tor Browser release that incorporated a vulnerable Firefox version was affected, though researchers have not identified the exact Tor releases.<\/p>\n<p>On its own, the bug runs code only inside Firefox&#8217;s sandboxed content process. Nebula <a href=\"https:\/\/github.com\/NebuSec\/CyberMeowfia\/commits\/main\/IonStack\/CVE-2026-10702\" target=\"_blank\">released public exploit material<\/a> and used the flaw as the first stage of IonStack, a browser-to-kernel chain built for an ARM64 device running Android 17. The released end-to-end code targets one supported Google build, although Zou said the browser flaw itself is not ARM-specific.<\/p>\n<p>The public code contains Firefox 151.0 offsets for the supported ARM64 Android 17 build. Zou said each exploitation step is architecture-independent and described the x86 path as more stable, although Nebula has not completed the full chain for that architecture.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-vuln-protection-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjQl2axNwsfhbXOFynrg_uAZsvHi3OvNGSA8KJO-BKR8Xm3x7yjKV3EvfY4v5mwXx6LF0uWFb9h9d9iAV_Pi-YYhqimX9wx4OaLdDJEdR215Xrxq_PAtXkaLfQso4pTSjbj6fvh_ZTliLpzWZSZfcoZgyXtKwhN-SSDDlmbtUqGLshc0KqYQGWYHMN52Sl1\/s728-e100\/zz-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Firefox users should update to the latest release. The Hacker News traced the faulty alias declaration through Mozilla&#8217;s source history to <a href=\"https:\/\/bugzilla.mozilla.org\/show_bug.cgi?id=1995077\" target=\"_blank\">Bug 1995077<\/a>, which landed for Firefox 147. The override is present in <a href=\"https:\/\/raw.githubusercontent.com\/mozilla-firefox\/firefox\/FIREFOX_151_0_2_RELEASE\/js\/src\/jit\/MIR.h\" target=\"_blank\">Firefox 151.0.2<\/a> and absent from <a href=\"https:\/\/raw.githubusercontent.com\/mozilla-firefox\/firefox\/FIREFOX_151_0_3_RELEASE\/js\/src\/jit\/MIR.h\" target=\"_blank\">Firefox 151.0.3<\/a>. That places the affected stable-release range at Firefox 147 through 151.0.2.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>Mozilla&#8217;s advisory does not list Firefox ESR, and the faulty override is absent from <a href=\"https:\/\/raw.githubusercontent.com\/mozilla-firefox\/firefox\/FIREFOX_140_12_0esr_RELEASE\/js\/src\/jit\/MIR.h\" target=\"_blank\">Firefox ESR 140.12<\/a>. As of July 28, 2026, the available primary-source record does not establish exploitation against users in the wild.<\/p>\n<p>In its <a href=\"https:\/\/nebusec.ai\/research\/ionstack-part-1-cve-2026-10702\/\" target=\"_blank\">technical analysis<\/a>, Nebula traces the issue to MObjectToIterator when it runs with skipRegistration set to true. Firefox&#8217;s just-in-time (JIT) compiler turns frequently run JavaScript into native machine code, and to do that safely it has to track which operations can touch memory.<\/p>\n<p>Firefox treated the operation as a read even though resolving a lazy property can allocate a replacement dynamic-slots buffer and free the old one.<\/p>\n<p>Global value numbering then treated a later slots-buffer load as redundant and reused the earlier pointer after it had become stale. Nebula&#8217;s <a href=\"https:\/\/github.com\/NebuSec\/CyberMeowfia\/blob\/main\/IonStack\/CVE-2026-10702\/exploit.html\" target=\"_blank\">released exploit<\/a> reclaims the freed allocation, leaks a hidden-class pointer, builds a fake object, and corrupts a Uint8Array to gain arbitrary memory read and write. The Android code then changes memory protections and redirects a WebAssembly function entry point to ARM64 shellcode.<\/p>\n<p>The failure turns on a narrow compiler contract: an operation capable of replacing the object&#8217;s dynamic-slots buffer was labelled as a read. That incorrect contract let otherwise valid optimisation logic preserve a pointer the runtime had already invalidated.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thn.news\/sygnia-webinar\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjnP2BIJTKZ31v-Y_pyvFqC1s6LD-Bo8UNy3UHgqojpVezgaGWw5-sPe5uRK0dfSm3gmDvoKCdHoJnGx1BiTP6Y0qit7D7TCZU_LckTDpdu9eeyuelmJKndEkOxZP6oNPwzguLBCTkAnNkIEvSYaWamKLqYLrJPjnea1V_lz7UcfQkavBo2g3OEGoLyz7mD\/s728-e100\/sygnia-d-4.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Mozilla&#8217;s <a href=\"https:\/\/github.com\/mozilla-firefox\/firefox\/commit\/e43e678\" target=\"_blank\">source-level fix<\/a> removes the custom read-only alias handling from ObjectToIterator and adjusts the related iterator operation. That prevents the optimiser from treating a mutation-capable step as a harmless load and retaining the stale pointer.<\/p>\n<p>IonStack&#8217;s second stage is CVE-2026-43499, a separate Linux kernel futex flaw that Nebula calls GhostLock. CVE-2026-10702 provides the remote browser foothold; CVE-2026-43499 carries it to root on the supported Android build.<\/p>\n<p>Zou said GhostLock is invoked directly from Firefox. He added that Android&#8217;s weaker sandbox makes exploitation easier, but Nebula does not believe a stronger desktop sandbox would prevent the attack.<\/p>\n<p>Updating Firefox blocks the documented browser entry point, but it does not patch GhostLock itself.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Swati Khandelwal\ue802Jul 29, 2026Vulnerability \/ Browser Security Nebula Security says a patched Firefox JIT flaw could be triggered by simply visiting a malicious webpage and was also used to compromise&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2084,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[265,869,33,605,2788,1461,2791,2790,2789],"class_list":["post-2083","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-browser","tag-compromise","tag-malicious","tag-researchers","tag-show","tag-single","tag-tor","tag-visit","tag-webpage"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2083","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2083"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2083\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2084"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2083"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2083"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2083"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}