Skip to main content

Tor users warned to update after critical Firefox bug allows identities to be discovered

Anyone using Tor to browse the web anonymously is being advised to update their browser immediately after a critical bug was discovered that allows an attacker to de-anonymize users. The vulnerability exists in Firefox, on which the Tor browser is based.

Mozilla said that the flaw is already being actively exploited on Windows, and that while there is as yet no indication of a similar exploit on macOS, the same vulnerability exists on all platforms.

The bug is fixed in the latest stable version of Firefox. For those on alpha and hardened versions, there are two ways you can protect yourself.

1) Set the security slider to “High” as this is preventing the exploit from working.

2) Switch to the stable series until updates for alpha and hardened are available, too.

If you’re using the stable version, you should update Firefox to 45.5.1esr and NoScript to 2.9.5.2.

ArsTechnica reports that the exploit allows both IP and MAC addresses to be captured by an attacker.

The attack executed code when targets loaded malicious JavaScript and code based on scalable animation vector graphics. The exploit used the capability to send the target’s IP and MAC address to an attacker-controlled server.

It’s been speculated that the exploit may have been created by the FBI, but is now in the wild. This risk is, of course, the reason Apple argued against the FBI’s demand that it create a special GovOS version of iOS.

FTC: We use income earning auto affiliate links. More.

You’re reading 9to5Mac — experts who break news about Apple and its surrounding ecosystem, day after day. Be sure to check out our homepage for all the latest news, and follow 9to5Mac on Twitter, Facebook, and LinkedIn to stay in the loop. Don’t know where to start? Check out our exclusive stories, reviews, how-tos, and subscribe to our YouTube channel

Comments

Author

Avatar for Ben Lovejoy Ben Lovejoy

Ben Lovejoy is a British technology writer and EU Editor for 9to5Mac. He’s known for his op-eds and diary pieces, exploring his experience of Apple products over time, for a more rounded review. He also writes fiction, with two technothriller novels, a couple of SF shorts and a rom-com!


Ben Lovejoy's favorite gear

Manage push notifications

notification icon
We would like to show you notifications for the latest news and updates.
notification icon
You are subscribed to notifications
notification icon
We would like to show you notifications for the latest news and updates.
notification icon
You are subscribed to notifications