Tor is one of the biggest open-source software, its networks have virtual tunnels that generally enable people and different groups to enhance their privacy and security on the Internet.
Recently Tor has released its Tor Browser 10.0.18, and the main motive of this release is to fix all the countless bugs, which also include a vulnerability that enables different websites to keep track of their users by fingerprinting the installed application.
We all know that Tor administers Internet traffic with the help of an overlay network that is free worldwide.
But, this network consists of nearly seven thousand relays, that help in concealing a user’s location as well as usage from people who are conducting network surveillance or traffic examination.
Scheme flooding is a vulnerability, that uses different custom URL schemes as an attack vector. According to the experts, this vulnerability generally enables the actors to identify that which applications have been installed by the users.
Once the experts identified the application successfully, then they use all the data and information of the installed app on the user’s computer.
And the main motive of doing this is that they want to assign a permanent unique identifier in the user’s computer so that they can use the system even if the users switch browsers just by using incognito mode or a VPN.
Not only this but scheme flooding also allows third-party tracking in a different browser. However, this exploit generally helps the hackers to track down the usage of users’ browsers like Google Chrome, Safari, even the Tor browser as well.
The experts have mentioned a full changelog for Tor 10.0.18, which is given below:-
All Platforms
Android
Build System
According to the security researchers, as well as Tor, this new version updates Tor to 0.4.5.9, and it consists of all the important security fixes.
While this new release also updates Firefox to 89.1.1, and NoScript to 11.2.8 and all this new version includes the important security updates to Firefox for Android.
You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity and hacking news updates.
Hackers have reportedly infiltrated and extracted a vast 82 GB of sensitive data from the Indonesian…
IBM has issued a security bulletin warning of two vulnerabilities in its AIX operating system…
The Apache Software Foundation has issued a security alert regarding a critical vulnerability in Apache…
The Chinese National Internet Emergency Center (CNIE) has revealed two significant cases of cyber espionage…
A critical command injection vulnerability in the popular systeminformation npm package has recently been disclosed, exposing millions…
Researchers discovered a malware campaign targeting the npm ecosystem, distributing the Skuld info stealer through…