Firefox Bug Unmasks Private and Tor Users
A recent vulnerability, known as CVE-2026-6770, allows attackers to exploit a Firefox bug that unmasks users, even those browsing in Private Mode or using the Tor Browser. This flaw, impacting Firefox’s IndexedDB, risks user privacy by exposing stable identifiers for cross-site tracking. Attackers can leverage this without any user interaction, posing significant privacy threats. Despite no known active exploits, Mozilla addressed the issue with updates to Firefox 150 and Thunderbird, while the Tor Project released Tor Browser 15.0.10.
Researchers pointed out sites could fingerprint a browser session, undermining privacy as identifiers persist throughout the browser process. The bug persists across Firefox Private Mode sessions and Tor’s New Identity feature, negating expected security. This vulnerability enables cross-origin tracking, which defies core privacy expectations of unlinked user activity. For those interested in further details about how this Firefox bug unmasks users and the broader implications, the full article is available at the following link:
Firefox bug CVE-2026-6770 enabled cross-site tracking and Tor fingerprinting
