REDHAT-BUG-1510816: Medium severity tor browser vulnerability
Tor Browser before 7.0.9 on macOS and Linux allows remote attackers to bypass the intended anonymity feature and discover a client IP address via vectors involving a crafted web site that leverages file:// mishandling in Firefox, aka TorMoil.
Upstream issue:
https://trac.torproject.org/projects/tor/ticket/24052
References:
https://blog.torproject.org/tor-browser-709-released https://www.bleepingcomputer.com/news/security/tormoil-vulnerability-leaks-real-ip-address-from-tor-browser-users/ https://www.wearesegment.com/research/tormoil-torbrowser-unspecified-critical-security-vulnerability/
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1510816?
The severity of REDHAT-BUG-1510816 is critical due to its potential to compromise user anonymity.
How do I fix REDHAT-BUG-1510816?
To fix REDHAT-BUG-1510816, update your Tor Browser to version 7.0.9 or later.
What platforms are affected by REDHAT-BUG-1510816?
REDHAT-BUG-1510816 affects Tor Browser on macOS and Linux platforms.
What is the exploit vector for REDHAT-BUG-1510816?
The exploit vector for REDHAT-BUG-1510816 involves file:// mishandling in Firefox that allows site-crafted attacks to leak IP addresses.
What are the implications of REDHAT-BUG-1510816 for user security?
The implications of REDHAT-BUG-1510816 for user security include the risk of exposing real IP addresses, potentially undermining anonymity efforts.