hacker-news · Crawled Jul 29, 2026
Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser
1 CVEs
Read original article ↗
AI Summary
A high-severity vulnerability in Firefox's JIT compiler, tracked as CVE-2026-10702, allows arbitrary code execution in the browser's renderer process simply by visiting a malicious webpage. This flaw affects Firefox versions 147 through 151.0.2 and also impacts Tor Browser versions based on these Firefox releases. The vulnerability was exploited in a browser-to-kernel chain called IonStack, combining it with a Linux kernel flaw (CVE-2026-43499, GhostLock) to achieve root access on ARM64 Android 17 devices. Mozilla has patched the issue in Firefox 151.0.3, but exploitation remains possible in unpatched systems.
AI-extracted · verify before operational use
Extracted Entities 1 found
MITRE ATT&CK TTPs 33 techniques
T1021.001 Remote Desktop Protocol · Lateral Movement T1021.003 Distributed Component Object Model · Lateral Movement T1055 Process Injection · Defense Evasion T1056.001 Keylogging · Collection T1059.001 PowerShell · Execution T1068 Exploitation for Privilege Escalation · Privilege Escalation T1071.001 Web Protocols · Command And Control T1071.004 DNS · Command And Control T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1098 Account Manipulation · Persistence T1105 Ingress Tool Transfer · Command And Control T1110 Brute Force · Credential Access T1114 Email Collection · Collection T1120 Peripheral Device Discovery · Discovery T1132 Data Encoding · Command And Control T1133 External Remote Services · Persistence T1185 Browser Session Hijacking · Collection T1190 Exploit Public-Facing Application · Initial Access T1202 Indirect Command Execution · Defense Evasion T1203 Exploitation for Client Execution · Execution T1210 Exploitation of Remote Services · Lateral Movement T1484.001 Group Policy Modification · Defense Evasion T1490 Inhibit System Recovery · Impact T1491 Defacement · Impact T1542 Pre-OS Boot · Defense Evasion T1543.003 Windows Service · Persistence T1557 Adversary-in-the-Middle · Credential Access T1566 Phishing · Initial Access T1573 Encrypted Channel · Command And Control T1588.001 Malware · Resource Development T1595 Active Scanning · Reconnaissance T1659 Content Injection · Initial Access