[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f85KxIMjehQi_GX2gqOBTehmnUhpQvls74FSt6iYi1fU":3},{"article":4,"iocs":55},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":34,"category":35,"article_tags":39},"0a8da848-8a8b-4329-8642-fdca92c9b6d1","Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser","researchers-show-a-single-malicious-webpage-visit-can-compromise-tor-browser-aab2a0","Nebula Security says a patched Firefox JIT flaw could be triggered by simply visiting a malicious webpage and was also used to compromise Tor Browser. Tracked as CVE-2026-10702, the bug provides arbitrary code execution inside the browser's renderer process. Mozilla rated it High and fixed it in the Firefox 151.0.3 update. \"No settings or additional user interaction are required,\" Eten Zou,","Nebula Security disclosed a patched Firefox just-in-time (JIT) compiler vulnerability (CVE-2026-10702) that enables arbitrary code execution in the browser's renderer process through a single malicious webpage visit with no user interaction required. The flaw affected Firefox versions 147 through 151.0.2 and all Tor Browser releases using vulnerable Firefox versions. Nebula released public exploit code demonstrating a full browser-to-kernel attack chain (IonStack) on ARM64 Android 17, chained with a separate Linux kernel futex vulnerability (CVE-2026-43499).","Firefox JIT flaw CVE-2026-10702 allows arbitrary code execution via malicious webpage visits, affecting Tor Browser.","Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser Swati KhandelwalJul 29, 2026Vulnerability \u002F Browser Security Nebula Security says a patched Firefox JIT flaw could be triggered by simply visiting a malicious webpage and was also used to compromise Tor Browser. Tracked as CVE-2026-10702, the bug provides arbitrary code execution inside the browser's renderer process. Mozilla rated it High and fixed it in the Firefox 151.0.3 update. \"No settings or additional user interaction are required,\" Eten Zou, CEO of Nebula Security, told The Hacker News. \"Visiting a malicious webpage is enough to trigger it,\" Zou said every Tor Browser release that incorporated a vulnerable Firefox version was affected, though researchers have not identified the exact Tor releases. On its own, the bug runs code only inside Firefox's sandboxed content process. Nebula released public exploit material and used the flaw as the first stage of IonStack, a browser-to-kernel chain built for an ARM64 device running Android 17. The released end-to-end code targets one supported Google build, although Zou said the browser flaw itself is not ARM-specific. The public code contains Firefox 151.0 offsets for the supported ARM64 Android 17 build. Zou said each exploitation step is architecture-independent and described the x86 path as more stable, although Nebula has not completed the full chain for that architecture. Firefox users should update to the latest release. The Hacker News traced the faulty alias declaration through Mozilla's source history to Bug 1995077, which landed for Firefox 147. The override is present in Firefox 151.0.2 and absent from Firefox 151.0.3. That places the affected stable-release range at Firefox 147 through 151.0.2. Mozilla's advisory does not list Firefox ESR, and the faulty override is absent from Firefox ESR 140.12. As of July 28, 2026, the available primary-source record does not establish exploitation against users in the wild. In its technical analysis, Nebula traces the issue to MObjectToIterator when it runs with skipRegistration set to true. Firefox's just-in-time (JIT) compiler turns frequently run JavaScript into native machine code, and to do that safely it has to track which operations can touch memory. Firefox treated the operation as a read even though resolving a lazy property can allocate a replacement dynamic-slots buffer and free the old one. Global value numbering then treated a later slots-buffer load as redundant and reused the earlier pointer after it had become stale. Nebula's released exploit reclaims the freed allocation, leaks a hidden-class pointer, builds a fake object, and corrupts a Uint8Array to gain arbitrary memory read and write. The Android code then changes memory protections and redirects a WebAssembly function entry point to ARM64 shellcode. The failure turns on a narrow compiler contract: an operation capable of replacing the object's dynamic-slots buffer was labelled as a read. That incorrect contract let otherwise valid optimisation logic preserve a pointer the runtime had already invalidated. Mozilla's source-level fix removes the custom read-only alias handling from ObjectToIterator and adjusts the related iterator operation. That prevents the optimiser from treating a mutation-capable step as a harmless load and retaining the stale pointer. IonStack's second stage is CVE-2026-43499, a separate Linux kernel futex flaw that Nebula calls GhostLock. CVE-2026-10702 provides the remote browser foothold; CVE-2026-43499 carries it to root on the supported Android build. Zou said GhostLock is invoked directly from Firefox. He added that Android's weaker sandbox makes exploitation easier, but Nebula does not believe a stronger desktop sandbox would prevent the attack. Updating Firefox blocks the documented browser entry point, but it does not patch GhostLock itself. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  Android, browser security, Cybersecurity Research, linux, mobile security, Open Source, Privacy, Vulnerability, Web Security ⚡ Top Stories This Week New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable ⭐ Featured Resources Identity Fraud Is Changing Fast. See the Attacks Businesses Face in 2026 What 25 Million Alerts Reveal About the Threats SOCs Ignore How to Find and Control Every Script Running Through Your Marketing Stack Modern SASE Guide: Close the Gaps Traditional Network Security Cannot See","https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Fresearchers-show-single-malicious.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEiOwFIxqT8kRBNj9LdZBZhO1g2RPJwUttxQosrS_mPoNXkIR-JB-yM87HPzuPZ1tazourGhRg9Sco6YQEGZkC77DSqXBYjp0DkNDAUHOaAOnIisRYNPAQfNWwqnmoILXOgR0wwyGVNlU3kSVRU6TcfyAx5ztaAWZfbKnCDJYgUeIVsM7n7O2zq7fGc-xnI\u002Fs1600\u002Ftor-exploit.gif","2026-07-29T11:57:00+00:00","2026-07-29T14:00:19.307567+00:00",9,[18,21,24,26,28,31],{"name":19,"type":20},"Mozilla","vendor",{"name":22,"type":23},"Firefox","product",{"name":25,"type":23},"Tor Browser",{"name":27,"type":20},"Nebula Security",{"name":29,"type":30},"IonStack","campaign",{"name":32,"type":33},"JIT compiler","technology","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":34,"icon":36,"name":37,"slug":38},null,"Vulnerabilities","vulnerabilities",[40,45,50],{"category":41},{"id":42,"icon":36,"name":43,"slug":44},"574f766a-fb3f-487c-8d2c-0720ae75471b","Zero-day","zero-day",{"category":46},{"id":47,"icon":36,"name":48,"slug":49},"614132b8-5837-4952-b8b5-c6c9a32a1d85","Privacy","privacy",{"category":51},{"id":52,"icon":36,"name":53,"slug":54},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",[56,60],{"type":57,"value":58,"context":59},"cve","CVE-2026-10702","Firefox JIT compiler flaw enabling arbitrary code execution via malicious webpage",{"type":57,"value":61,"context":62},"CVE-2026-43499","Linux kernel futex vulnerability (GhostLock) used as second stage in IonStack exploit chain"]