importantSYS.SOURCE: The Hacker News• 2026-07-29T17:27:00+05:30
Critical Firefox JIT Flaw Enables Remote Compromise of Tor Browser
A critical Firefox JIT compiler vulnerability (CVE-2026-10702) allows remote code execution through a malicious webpage, compromising Tor Browser without user interaction. The exploit chain, IonStack, combines the browser flaw with a Linux kernel futex vulnerability (CVE-2026-43499) to achieve privilege escalation on Android.
Nebula Security says a patched Firefox JIT flaw could be triggered by simply visiting a malicious webpage and was also used to compromise Tor Browser.
Tracked as CVE-2026-10702, the bug provides arbitrary code execution inside the browser's renderer process. Mozilla rated it High and fixed it in the Firefox 151.0.3 update.
"No settings or additional user interaction are required," Eten Zou,
*** END OF TRANSMISSION ***