Mozilla, Tor Issue Critical Update for Actively Exploited Firefox Vulnerability

Advertisement
By Roydon Cerejo | Updated: 1 December 2016 16:26 IST
Highlights
  • The browser vulnerability is being exploited on the Widows platform
  • Reports say the code was intended for lawful purposes, which went public
  • Tor and Mozilla have both rolled out updates to curb this exploit

An unknown Firefox vulnerability which originally came to light in a post on the official Tor website, has now been fixed by Mozilla and Tor. The exploit takes advantage of a memory corruption vulnerability that allows malicious payload to send the targets IP and MAC address to an anonymous server.

The Motherboard found several reports that point to this code being used on a Tor hidden service called the Giftbox, which is used to peddle child pornography. This is very similar to the technique used by the FBI back in 2013 to identify users who were trading child pornography, over the Tor network. However, now that this very same code is out in the wild, anyone can exploit it with some changes to the code.

Daniel Veditz from Mozilla, stated in a blog post, “This similarity has led to speculation that this exploit was created by FBI or another law enforcement agency. As of now, we do not know whether this is the case. If this exploit was in fact developed and deployed by a government agency, the fact that it has been published and can now be used by anyone to attack Firefox users is a clear demonstration of how supposedly limited government hacking can become a threat to the broader Web.” Mozilla issued an update to Firefox on Wednesday that it says will roll out automatically to existing users - but users can also update their browsers via the company site.

Advertisement

The Tor browser is built using Firefox as its base. The latest version (6.0.7) is now available for download and is said to fix this issue. The official Tor blog post states that this security flaw is currently being actively exploited on Windows systems and that Mac and Linux users are most likely also affected, although the exploit is being actively present on the latter to platforms as of now.

Advertisement

The blog post by Tor strongly recommends updating the browser immediately if that’s something you use for surfing the Web. If you have the security slider set to ‘High’ then your chances are better, although doing so might prevent most websites that use JavaScript from working properly. Updates to the alpha and hardened versions of Tor are on the way so till then, it’s recommended to switch to the stable release.

 

For details of the latest launches and news from Samsung, Xiaomi, Realme, OnePlus, Oppo and other companies at the Mobile World Congress in Barcelona, visit our MWC 2025 hub.

Advertisement
Popular Mobile Brands
  1. Nothing Phone 4a, Phone 4a Pro Launched in India at This Price
  2. Moto Watch Review: The Best Smartwatch Under Rs. 6,000 in 2026?
  3. Vivo T5x 5G AnTuTu Score Exceeds 1 Million Points, Will Launch in India Soon
  4. Nothing Launches Headphone (a) With Adaptive ANC, Spatial Audio Support
  5. OnePlus 15T Confirmed to Launch With a Larger Battery, Faster Charging
  6. Realme Narzo Power 5G With 10,001mAh Battery Launched in India: Price, Specifications
  7. Lava Bold 2 5G India Launch Teased; Company Teases Design Ahead of Debut
  8. Vivo X300 FE Launched as Global Version of This Chinese Smartphone
  9. Just a Day After Releasing GPT-5.3 Instant, OpenAI Teases GPT-5.4 Model
  10. MacBook Neo Launched in India With 13-Inch Display, A18 Pro Chip: See Price
  1. OpenAI Teases GPT-5.4 AI Model Launch Just a Day After Releasing GPT-5.3 Instant
  2. Nothing Headphone (a) Launched With Adaptive ANC, Customisable Controls: Price, Specifications
  3. Granny OTT Release Date: When and Where to Watch the Village Mystery Thriller Online?
  4. Andhaka OTT Release: Where to Watch the Telugu Drama-Thriller Online?
  5. Pookie OTT Release: When and Where to Watch Vijay Antony’s Romantic Drama Online?
  6. WhatsApp Plus Paid Subscription Reportedly in Development With Additional Customisation Options, Up to 20 Pinned Chats
  7. Samsung Patent Hints at Potential Clamshell-Style Foldable With Two Cover Displays
  8. Google Introduces Gemini 3.1 Flash-Lite as Its Fastest and Most Cost-Efficient AI Model
  9. Nothing Phone 4a Launched in India With Glyph Bar Interface Alongside Nothing Phone 4a Pro: Price, Specs
  10. Oppo Find N6 Key Features, Colour Options Leaked Ahead of Imminent China Launch
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.