Firefox and Tor Browser were treating IndexedDB name order as a browser-wide identifier. That breaks the assumption that Private Browsing and Tor’s New Identity mode keep unrelated sites from linking the same user across sessions until the browser is fully restarted. CVE-2026-6770 affects Mozilla Firefox and Tor Browser. Mozilla fixed it in Firefox 150, and Tor Project shipped the patch in Tor Browser 15.0.10. The flaw lets separate sites observe the same database ordering and use it to fingerprint a user without cookies or shared storage. The risk is not just tracking inside one tab or one session. It creates a cross-site identifier that survives reloads and new private sessions, so isolation features can fail even when users think they have reset their identity.
Part of the PlainSec briefing for 2026-04-27