CVE-2026-6770
CVSS 6.5 MEDIUM: other issue in the Storage: IndexedDB component. EPSS 5% (91st percentile), up from 0.07%.
Vulnerabilities & Exploits · Web App Attack
Firefox and Tor Browser were treating IndexedDB name order as a browser-wide identifier. That breaks the assumption that Private Browsing and Tor’s New Identity mode keep unrelated sites from linking the same user across sessions until the browser is fully restarted.
CVE-2026-6770 affects Mozilla Firefox and Tor Browser. Mozilla fixed it in Firefox 150, and Tor Project shipped the patch in Tor Browser 15.0.10. The flaw lets separate sites observe the same database ordering and use it to fingerprint a user without cookies or shared storage.
The risk is not just tracking inside one tab or one session. It creates a cross-site identifier that survives reloads and new private sessions, so isolation features can fail even when users think they have reset their identity.
1 source · Apr 27
CVSS 6.5 MEDIUM: other issue in the Storage: IndexedDB component. EPSS 5% (91st percentile), up from 0.07%.
SecurityWeek
Firefox Vulnerability Allows Tor User Fingerprinting
The vulnerability is tracked as CVE-2026-6770 and it has been patched with the release of Firefox 150 and Tor 15.0.10.
originalPart of the PlainSec briefing for 2026-04-27
Every edition of this story: Private Browsing Leaks a Stable Cross-Site Identifier