CVE-2021-39246: Medium severity torproject Tor Browser vulnerability
Tor Browser through 10.5.6 and 11.x through 11.0a4 allows a correlation attack that can compromise the privacy of visits to v2 onion addresses. Exact timestamps of these onion-service visits are logged locally, and an attacker might be able to compare them to timestamp data collected by the destination server (or collected by a rogue site within the Tor network).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-39246?
CVE-2021-39246 is a vulnerability in Tor Browser versions 10.5.6 and 11.x through 11.0a4 that allows a correlation attack compromising the privacy of visits to v2 onion addresses.
How does CVE-2021-39246 affect Tor Browser?
CVE-2021-39246 affects Tor Browser versions 10.5.6 and 11.x through 11.0a4 by enabling a correlation attack that compromises the privacy of visits to v2 onion addresses.
What is the severity of CVE-2021-39246?
The severity of CVE-2021-39246 is medium with a CVSS score of 6.1.
How can CVE-2021-39246 be exploited?
CVE-2021-39246 can be exploited by an attacker comparing exact timestamps of locally logged onion-service visits to timestamp data collected by the destination.
Is Apple macOS or Linux Linux kernel affected by CVE-2021-39246?
No, Apple macOS and Linux Linux kernel are not affected by CVE-2021-39246.