HomeSecurityTor Browser Zero Day Vulnerability Revealed on Twitter

Tor Browser Zero Day Vulnerability Revealed on Twitter

vulnerabilityA zero-day vulnerability for the Tor browser was disclosed yesterday on Twitter by Zerodium – a company that buys and sells software exploits.

Zerodium published the details of the vulnerability that existed in the Firefox NoScript extension (integrated into the Tor browser), which prevents websites from executing JavaScript, Flash, or Silverlight.

Although NoScript is supposed to block all JavaScript at its “safest” security level, there is a backdoor that can be exploited by attackers to suppress NoScript and execute malicious code.

However, this bug can only be exploited in Tor Browser 7.x, while the recently released Tor Browser 8.x is not affected by it.

The reason behind this is the change of Tor's codebase from the older Firefox engine to the new Firefox Quantum platform. The new add-on API protects version 8 from this vulnerability.

Aside from that, the NoScript add-on was rewritten last year to be compatible with the new Firefox Quantum platform. This is the reason why the mentioned zero-day vulnerability does not work in the new Tor Browser 8.x series.

After the disclosure by Zerodium, the company released the NoScript “Classic” version 5.1.8.7 to stop the zero-day exploitation.

Nevertheless, it is recommended that Tor users install the updated version of NoScript or switch to Tor Browser 8.x for greater security.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS