The Tor Project has released a security update for the Tor Browser on Mac and Linux to fix a vulnerability that leaks users' real IP addresses. The vulnerability was spotted by Filippo Cavallarin, CEO of We Are Segment, an Italian company specialized in cyber-security and ethical hacking. Cavallarin privately reported the issue — which he codenamed TorMoil — to the Tor Project last week. Tor Project developers worked with the Firefox team (Tor Browser is based on the Firefox browser) to release a fix. Today, the Tor team released version 7.0.9 to address the vulnerability. Tor Browser 7.0.9 is only available for Mac and Linux users. Tor Browser on Windows is not affected. According to Cavallarin, the issue is actually a Firefox bug in the way the browser handles file:// URLs. While the issue is harmless in Firefox, it's catastrophic in the Tor Browser. "Once an affected [Tor Browser] user navigates to a specially crafted web page, the operating system may directly connect to the remote host, bypassing Tor Browser," Cavallarin said. By directly connecting to the page, the Tor Browser will not go through the network of Tor relays, exposing the user's real-world IP address. "We are not aware of this vulnerability being exploited in the wild," the Tor Project said today in a statement. Nonetheless, an attacker can reverse engineer the Tor Browser binary and detect the patched code. A well-versed programmer can then very easily understand how the bug occurs and create an exploit ...
TorMoil Vulnerability Leaks Real IP Address from Tor Browser Users
BleepingComputer
·Published Nov 3, 2017
·Updated
Affected Software
3 affected components
Tor Project Tor Browser (Mac)<7.0.9
Tor Project Tor Browser (Linux)<7.0.9
Mozilla Firefox
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a vulnerability in the Tor Browser that leaks users' real IP addresses.
2
What security implications are discussed in the article?
The vulnerability could compromise the anonymity of Tor Browser users by exposing their real IP addresses.
3
What products or software are affected by the vulnerability?
The vulnerability affects the Tor Browser on Mac and Linux, as well as Mozilla Firefox.
4
Who discovered the TorMoil vulnerability?
The vulnerability was discovered by Filippo Cavallarin, CEO of We Are Segment.
5
What has the Tor Project done in response to the vulnerability?
The Tor Project has released a security update to fix the vulnerability in the Tor Browser.