What are you saying here? It doesn’t seem like accessing Tor through a VPN would prevent this attack.
Tor browser should be developed based on Chromium
I’m not so sure about that. Chromium has a strong security architecture, but V8 has had more than enough serious JIT and memory corruption vulnerabilities of its own. With considerably more confirmed in the wild engine exploits than Firefox’s JavaScript engine in recent years.
Chromium has more vulnerabilities discovered can also mean that Google offers more rewards and that more people are interested in it.
Yes, there was a time when V8 had at least one big vulnerability per month.
Though it CAN be disabled, and in hardened environments it SHOULD be disabled. I still think Chromium has better security posture than Firefox.
Security is essential for privacy/anonymity.
This was patched by us months ago, long before the PoC you see here was released according to the researchers who developed this. We don’t keep older versions of GrapheneOS to know how functional it actually was, but for simplicity we’ll act on the assumption the entire exploit chain worked.
As it stands you need both a vulnerable version of an OS and Firefox (which they link as Firefox also patched) to do this. You should never install outdated applications, and as a plus we tell people in our usage guide to not use Firefox because the security of the mobile browser is poor.
—final
That’s a good thing.
Google currently spends tons of resources finding and fixing exploits with the help of powerful LLMs. So do other security researchers.
You don’t seem to take into account that barely anyone uses Firefox. Its market share is 3.33%, which is even lower than Edge’s 5.21%.
This is literally the same as me using TempleOS and saying, “But Fedora Linux, macOS, and Windows have more exploits than TempleOS, therefore, TempleOS is more secure.”
The fact is that the Chromium security team has more resources, and that Chromium has by far the most users and security researchers looking over the code. Which obviously will result in more vulnerabilities being found and fixed.
There’s a reason I specifically referred to confirmed in the wild exploitation rather than vulnerability totals.
Google’s budget, AI tooling (which Mozilla is also using) and bigger research system can explain why more Chromium vulnerabilities are discovered and reported. Chromium’s market share also helps explain why attackers target it more frequently.
But none of that changes my actual point, V8 vulnerabilities have been weaponized and exploited in real attacks. I never said this makes Firefox is inherently more secure. I was trying to say serious and exploitable JIT and memory corruption issues are not unique to Firefox, so claiming Tor would avoid this entire category of threat by switching to Chromium is wrong.
Firefox may even benefit somewhat from being a smaller general purpose target, but Tor itself certainly does not fly under the radar. Its users can be particularly valuable targets, regardless of its overall market share.
And comparing Firefox to TempleOS is a false equivalence. That’s like calling the Mets a neighborhood softball team because the Yankees have more fans. Chromium’s lead is enormous, but Firefox is still playing in the major leagues and not exactly running out of somebody’s basement.
I recall reading a long time ago that the reason for sticking woth firefox is that chromium still does not have proper proxy support.
In the wild exploitation cannot be accurately measured because most attacks leave no public record, and successful attackers deliberately try to remain undetected.
Nobody claimed that switching to Chromium would solve every issue. The only claim was that Chromium offers significantly stronger security and defenses, which is why Tor Browser would ideally be based on Chromium.
Chromium’s market share is 70%, while Firefox’s is only 3%, which makes Firefox niche. That was the point.
The problem is that SOCKS5 authentication is unsupported and Tor uses SOCKS5 usernames and passwords to isolate different streams onto separate circuits.