🟠 High  |  Source: The Hacker News


A patched vulnerability in Firefox’s JIT compiler (CVE-2026-10702) allows arbitrary code execution within the browser’s renderer process simply by visiting a malicious webpage — no user interaction beyond the visit is required. The flaw also affected Tor Browser, raising particular concern for users who rely on it for anonymity and privacy. Mozilla rated the issue High severity and addressed it in Firefox 151.0.3.

Security Architect’s Take: Ensure Firefox and Tor Browser are updated to 151.0.3 or later across all managed endpoints immediately; consider enforcing browser version compliance via endpoint management tooling and review whether any privileged or sensitive workloads are being accessed via unmanaged browsers that may still be on vulnerable versions.

Original advisory: Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser