Categories: Security

Tor Browser Bug ‘Could Leak Users’ Real IP Addresses’

The Tor Browser, used to navigate web pages without disclosing the user’s identity, has been hit by a security bug that could leak a user’s real internet address, the project has confirmed.

Security firm We Are Segment notified the Tor project of an issue affecting the Mac and Linux versions of the browser late last month, and an update was released on Friday with a temporary fix.

Researchers said they wouldn’t disclose details of the issue until a permanent fix was available.

But they said the vulnerability affects the way the Firefox browser handles pages using the “file://” protocol, used to navigate file repositories.

Tor network ‘bypassed’

The Tor Browser is based on Mozilla’s Firefox.

“Once an affected user navigates to a specially crafted web page, the operating system may directly connect to the remote host, bypassing Tor Browser,” We Are Segment said in an advisory.

The Tor project released version 7.0.9 of its browser on Friday, and on Monday patched the alpha testing version of the browser with version 7.5a7.

The project said users of Tails, a privacy-oriented Linux distribution developed by Tor, aren’t affected by the Linux version of the bug, and a sandboxed Tor browser currently in alpha testing is also unaffected.

Workaround

“We are not aware of this vulnerability being exploited in the wild,” Tor developers said in a blog post.

The project said its temporary fix may cause issues with navigating to “file://” addresses, including breaking links found on such pages.

Tor developers said Mozilla is working on a fix for Firefox which will then be incorporated into the Tor Browser.

Tor is used by those looking for anonymity, but has also been “>linked to criminal websites selling contraband such as drugs or outlawed weapons.

The now-defunct Silk Road contraband site operated as a Tor hidden service, taking payments in the Bitcoin cryptocurrency.

Do you know all about security in 2017? Try our quiz!

Matthew Broersma

Matt Broersma is a long standing tech freelance, who has worked for Ziff-Davis, ZDnet and other leading publications

Recent Posts

Apple, Google Mobile Ecosystems Should Be Investigated, CMA Told

CMA receives 'provisional recommendation' from independent inquiry that Apple,Google mobile ecosystem needs investigation

2 days ago

Australia Rejects Elon Musk Claim About Social Media Ban For Under-16s

Government minister flatly rejects Elon Musk's “unsurprising” allegation that Australian government seeks control of Internet…

2 days ago

Northvolt Files For Bankruptcy Protection In US

Northvolt files for Chapter 11 bankruptcy protection in the United States, and CEO and co-founder…

2 days ago

UK’s CMA Readies Cloud Sector “Behavioural” Remedies – Report

Targetting AWS, Microsoft? British competition regulator soon to announce “behavioural” remedies for cloud sector

3 days ago

Former Policy Boss At X, Nick Pickles, Joins Sam Altman Venture

Move to Elon Musk rival. Former senior executive at X joins Sam Altman's venture formerly…

3 days ago

Bitcoin Rises Above $96,000 Amid Trump Optimism

Bitcoin price rises towards $100,000, amid investor optimism of friendlier US regulatory landscape under Donald…

3 days ago