CVE-2026-10702
CVSS 4.3 MEDIUM: jIT miscompilation in the JavaScript Engine: JIT component. EPSS 0.9% (56th percentile).
Vulnerabilities & Exploits · Zero-Day Exploit
A browser sandbox is not the end of the risk here. A single malicious webpage can drive code execution in Firefox, and Nebula showed that same browser-side flaw can be chained into an Android kernel bug for root on an affected Android 17 build; Tor Browser inherits the Firefox-side exposure because it uses the same base engine.
Nebula published working exploit material for CVE-2026-10702, the Firefox JIT flaw fixed in Firefox 151.0.3. The public code also ties it to CVE-2026-43499, a kernel futex bug, and the reported chain targets one supported Google Android 17 build; Mozilla says the browser flaw is patched, but any Tor Browser release built on the vulnerable Firefox version remains exposed on the browser side.
The practical break is in the containment assumption. If a browser compromise can hand off to a local kernel bug, then patching the browser closes only part of the problem and managed mobile builds need to be treated as a chained-risk surface, not a sandboxed one.
1 source · Jul 29
CVSS 4.3 MEDIUM: jIT miscompilation in the JavaScript Engine: JIT component. EPSS 0.9% (56th percentile).
CVSS 7.8 HIGH: in the Linux kernel, the following vulnerability has been resolved: rtmutex: Use waiter::task instead of current in… EPSS 0.8% (54th percentile).
The Hacker News
Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser
Nebula says CVE-2026-10702 lets a malicious webpage compromise Tor Browser and start an Android 17 root chain.
originalPart of the PlainSec briefing for 2026-07-29
Every edition of this story: One Malicious Page Can Reach Android Root