Can we expect a stable Tor Browser release soon? ESR 91.6.1 appears to fix some critical security issues

Can we expect a stable Tor Browser release soon? ESR 91.6.1 appears to fix some critical security issues:

– Firefox ESR 91.6.1 is out with critical security fixes –

"The official release notes[1] list the following fixed security vulnerabilities in the Firefox releases:

  • Critical – CVE-2022-26485: Use-after-free in XSLT parameter processing

Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw.

  • Critical – CVE-2022-26486: Use-after-free in WebGPU IPC Framework

An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw.

Both vulnerabilities have a severity rating of critical, the highest rating available. Mozilla notes that both vulnerabilities are exploited in the wild, but it is unclear how widespread the attacks are. The linked bugs are not public.

Firefox users are encouraged to update their browsers as soon as possible to protect the browser and data against attacks targeting the vulnerabilities."

= Firefox 97.0.2 and Firefox ESR 91.6.1 are out with critical security fixes - gHacks Tech News

[1] Security Vulnerabilities fixed in Firefox 97.0.2, Firefox ESR 91.6.1, Firefox for Android 97.3.0, and Focus 97.3.0 — Mozilla

1 Like

Yes! A stable Tor Browser release (11.0.7) is scheduled for this week.

3 Likes

This topic was automatically closed 2 hours after the last reply. New replies are no longer allowed.

are we getting a v11.0.7 to fix the 2 security holes that were patched in firefox in v97.0.2?

Update: Tor Browser 11.0.7 has been released with the security updates. Please update your browsers!

3 Likes