Security News > 2020 > March > Tor browser fixes bug that allows JavaScript to run when disabled

Tor browser fixes bug that allows JavaScript to run when disabled
2020-03-17 12:16

The Tor browser has fixed a bug that could have allowed JavaScript to execute on websites even when users think they've disabled it for maximum anonymity.

The Tor Project revealed the issue in the release notes for version 9.0.6, initially suggesting users manually disable JavaScript for the time being if the issue bothered them.

Whether the issue matters depends on how users have configured Tor to treat JavaScript.

Tor's 'standard' setting enabled JavaScript by default, which users can upgrade to either 'safer', which disables JavaScript on non-HTTPS sites, or 'safest', which disables JavaScript completely.

Leaving JavaScript enabled opens users to the hypothetical risk that their anonymity might be compromised, for example using a vulnerability in the underlying Firefox browser.


News URL

https://nakedsecurity.sophos.com/2020/03/17/tor-browser-fixes-bug-that-allows-javascript-to-run-when-disabled/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
TOR 1 2 46 3 4 55