CVE Tools
Back to feed
Exploitation report Firefox rce Tor Browser Mozilla web-app

Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser

The Hacker News·By The Hacker News··3 min read
CVE Tools coverage

Researchers from Nebula Security revealed that a malicious webpage visit alone could exploit a recently patched vulnerability in Firefox, which also impacted Tor Browser. Tracked as CVE-2026-10702, the flaw allows arbitrary code execution within the browser’s renderer process and was rated High by Mozilla. It was addressed in the Firefox 151.0.3 update. The vulnerability stems from an incorrect classification of a JavaScript operation during just-in-time compilation, leading to potential memory corruption. Public exploit code has been shared, demonstrating how this flaw can serve as the initial stage in a broader exploitation chain targeting Android devices. Users are advised to update their browsers immediately to mitigate risk.