logo

Firefox bug CVE-2026-6770 enabled cross-site tracking and Tor fingerprinting

ID: c1ab1fd9-0ad1-5864-ae92-48c9d339d5bc

STIX ID: report--c1ab1fd9-0ad1-5864-ae92-48c9d339d5bc

Feed Name: Security Affairs

Threat Score
50/100

Date Published: 2026-04-27

Date Updated: 2026-04-27

Author: Pierluigi Paganini

...
...

Firefox, Thunderbird and Tor Browser were affected by CVE-2026-6770: an IndexedDB information-disclosure flaw that allowed websites to derive a stable, process-scoped fingerprint from the ordering of indexedDB.databases(), enabling cross-origin tracking that persists across Private Browsing windows and Tor "New Identity" sessions; Mozilla and the Tor Project released patches (Firefox 150, ESR 140.10, Thunderbird updates and Tor Browser 15.0.10) to remediate the issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.