SECURITY·중요도 9·2026. 07. 29.·The Hacker News

Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser

── KO ──────────────────

연구자들이 악성 웹페이지 방문만으로 Tor 브라우저가 타격을 받을 수 있음을 보여주었다.

Nebula Security는 패치된 Firefox JIT 결함이 악성 웹페이지 방문만으로 발생할 수 있으며, 이는 Tor 브라우저를 위협할 수도 있음을 밝혔다. 이 결함은 CVE-2026-10702로 추적되며, 브라우저의 렌더러 프로세스 내에서 임의 코드 실행을 제공한다. Mozilla는 이 문제를 높은 위험도로 분류하고 Firefox 151.0.3 업데이트에서 이를 수정하였다.


── EN ──────────────────

Researchers have shown that visiting a malicious webpage can compromise the Tor Browser.

Nebula Security revealed that a patched Firefox JIT flaw could be triggered by simply visiting a malicious webpage, potentially compromising the Tor Browser. Tracked as CVE-2026-10702, the bug allows arbitrary code execution within the browser's renderer process. Mozilla rated this issue as High and addressed it in the Firefox 151.0.3 update.

원문 보기 →목록으로