Video wird geladen...
Video konnte nicht geladen werden
Watch us open the camera and uncover the anonymous identity behind Tor browser: We published the writeup for the browser RCE in IonStack. Mythos reported 271 bugs in Firefox 150 but still missed this one. And the Tor Browser is also affected by CVE-2026-10702. Update your Tor!
74,105 Aufrufe • vor 1 Monat •via X (Twitter)
18 Kommentare

IonBanana (CVE-2026-10702) was fixed in Firefox 151.0.3. Tor Browser stable tracks Firefox ESR and backported it in 15.0.19 on July 21. Our full writeup:

Wait, tor?

But luckily we managed to protect people using Tor this time.

Try it on Qubes Whonix VM lmao. Android TBB has a very bad sandbox.

🎶 @roddux

Try this against a grapheneOS device. Where camera is turned off. I doubt it will work.

Nice work! I'd like to see an exploit of the browser running on Tails that gains access to unmounted disks on the host system.

Holly sh***** !!!!!

Anyone who believes Tor or any other form of encryption is safe, is a fool.

Tor on Android in particular is always going to be less secure when you use a mobile data connection with the default DNS. But you seem to be using WiFi so you're all good. Your cats are amazing btw

WHO is so stupid to scan an unknown QR code ?.

Mythos found 271 bugs but missed this RCE. CVE-2026-10702. Patching my Tor install now.

One reason to not scan random QR codes.

🤝🤝

Nonsense.

don't stop. keep shoving those qr codes into our lives. i'll always get for a physical menu...

Your Tor becomes their Backdoor

meh

