Tor v15.0.19 is now available, and it’s a security-focused update. It’s based on Firefox ESR 140.13.0 and includes important security patches for multiple vulnerabilities.
The official changelog for Windows, macOS, Linux, and Android was posted on the Tor blog. You can take a look at the list of fixes in the image attached below.
NoScript is a critical built-in security extension in Tor, and it blocks JavaScript, Java, etc by default, allowing it only on sites you explicitly trust. This is one of the strongest protections against several exploits. This update bumps up NoScript to 13.6.31.1984, which is more secure since it contains several changes of its own.
Furthermore, the “Funding the Commons Implementations” have been removed on all platforms. The Tor Project partnered with them before, and the code related to that campaign was temporarily added to Tor. Now, it has been reverted, since the campaign has ended.
Additionally, the Tor team has also updated to the latest official Mozilla Firefox ESR (v140.13.0esr). It also brings all the security fixes from Firefox 153. Mozilla has published information about these vulnerabilities, which have been patched. ESR140.13 fixes an invalid pointer in the JavaScript WebAssembly component, and also a “site isolation failure.”
Mozilla also notes that both of these issues have public exploit code available, but the company isn’t aware of them being exploited yet.
For Android, this version updates GeckoView to 140.13.0esr. GeckoView is the Android embedding of the Gecko engine, and the Tor browser for Android doesn’t use the entire Firefox desktop codebase.
The rest are just build/system changes which don’t affect end users. They’re for developer use.
While this isn’t a release that’s focused on features, it still brings important security updates. If you haven’t updated already, we’d recommend updating immediately.
The post Tor browser v15.0.19 patches multiple critical security vulnerabilities appeared first on PiunikaWeb.