A browser sandbox is not the end of the risk here. A single malicious webpage can drive code execution in Firefox, and Nebula showed that same browser-side flaw can be chained into an Android kernel bug for root on an affected Android 17 build; Tor Browser inherits the Firefox-side exposure because it uses the same base engine.
Nebula published working exploit material for CVE-2026-10702, the Firefox JIT flaw fixed in Firefox 151.0.3. The public code also ties it to CVE-2026-43499, a kernel futex bug, and the reported chain targets one supported Google Android 17 build; Mozilla says the browser flaw is patched, but any Tor Browser release built on the vulnerable Firefox version remains exposed on the browser side.
The practical break is in the containment assumption. If a browser compromise can hand off to a local kernel bug, then patching the browser closes only part of the problem and managed mobile builds need to be treated as a chained-risk surface, not a sandboxed one.