Tails developers have warned users to stop using the Debian-based portable Linux distro until the next release if they are using it to access sensitive information through the bundled Tor Browser application.
See also: Microsoft: Huge increase in Linux XorDDoS malware activity

Tails (short for The Amnesic Incognito Live System) is a Linux distro focused on protecting the anonymity of users (e.g. activists and journalists) and helping them bypass censorship by forcing all connections to and from the Internet through the Tor network.
“We recommend that you stop using Tails until the release of 5.1 (May 31) if you use Tor Browser for sensitive information (passwords, private messages, personal information , etc.),” the Tails developers warned.
This warning was caused by two critical zero-day bugs in Firefox 's JavaScript engine (tracked as CVE-2022-1802 and CVE-2022-1529), which were exploited during the first day of the Pwn2Own 2022 Vancouver hacking competition and were patched by Mozilla two days later.
While the bugs have already been fixed upstream, the developers cannot deliver patches for any of the included applications until the next release, since Tails is a live Linux distro
The vulnerabilities allow attackers to access information from other websites visited using the Tor browser , if successfully exploited .
See also: Linux: Chromebooks are ideal for learning the operating system
“For example, after you visit a malicious website, an attacker controlling that website may gain access to your password or other sensitive information that you send to other websites subsequently during the same Tails session,” the Tails advisory adds.

Tails is still safe for some users
Tails developers explained that the flaws do not affect Tor Browser users when used at the safest security level, because it automatically disables JavaScript while browsing.
Similarly, Thunderbird users are not affected because the version that comes with the Tails Linux distro has JavaScript disabled by default.
Additionally, Tails users who do not use or access sensitive information through the Tor browser can use it safely, as the security flaws do not breach the encryption and anonymity of Tor connections.
See also: Nvidia: Linux GPU drivers will be open source
"Mozilla is already aware of websites exploiting this vulnerability. This vulnerability will be fixed in Tails 5.1 (May 31), but our team does not have the ability to release an emergency release sooner," the Tails team warned.
Information source: bleepingcomputer.com
