Tor Browser 6.0.7 is released

Tor Browser 6.0.7 is now available from the Tor Browser Project page and also from our distribution directory.

This release features an important security update to Firefox and contains, in addition to that, an update to NoScript (

The security flaw responsible for this urgent release is already actively exploited on Windows systems. Even though there is currently, to the best of our knowledge, no similar exploit for OS X or Linux users available the underlying bug affects those platforms as well. Thus we strongly recommend that all users apply the update to their Tor Browser immediately. A restart is required for it to take effect.

Tor Browser users who had set their security slider to "High" are believed to have been safe from this vulnerability.

We will have alpha and hardened Tor Browser updates out shortly. In the meantime, users of these series can mitigate the security flaw in at least two ways:

1) Set the security slider to "High" as this is preventing the exploit from working.
2) Switch to the stable series until updates for alpha and hardened are available, too.

Here is the full changelog since 6.0.6:

  • All Platforms
    • Update Firefox to 45.5.1esr
    • Update NoScript to

November 30, 2016


Could you explain where to find the security slider bar? I went into options, security but didn't see a slider bar. Thank you

Click on the green onion, choose "Privacy and Security Settings", and you should see the security slider.

There's also a little line that appears on the very first launch of Tor Browser, saying something like "Hey there's a security slider, check it out!"

so the browser auto updated on me and now when i start the tor app it takes me to the bare bones firefox browser and wont let me connect to .onion sites.... any ideas?

Hm... this is weird. On which operating system did this happen? Do you know from which version you updated? Did you have your Tor Browser modified? Anyway, it seems a safe bet is to download a fresh copy from our website: Still puzzling as you are the only one reporting this so far.

EDIT: Before you are deleting the non-functioning Tor Browser could you make a copy of it and pack it up and maybe make it available somewhere to us for further inspection? I'd be very interested to understand what went wrong in your case.


Thank you for all the great work.
Please don't take this as a complaint; is there any kind of a rough estimate on the general timeframe for Orfox to get this update on F-Droid, or is the vulnerability desktop only?
Keep fighting censorship and oppression, this world is going to hell in a handbasket and Tor is the only beacon of hope for citizens of totalitarian dictatorships.

i agree with your point..

my point would be there should be at least an rss feed or the sort that which we can subscribe to that let us know if any tor friendly software outside the the tor project that been updated for what ever reason.


Would this exploit work even on Selfrando? What about with the sandboxed Tor Browser by the end of this year?

> What about with the sandboxed Tor Browser by the end of this year?

It would probably crash the browser, because preventing crashes isn't something the sandbox is supposed to do.

However, assuming there was a Linux payload, it would need to be a lot more sophisticated than "get the IP address, and phone home" because the sandbox that firefox has, doesn't have an IP address, or a direct connection to the internet.

Sort of. It talks to a surrogate service that looks enough like the control port for the various things that need the control port to work. Depending on how the sandbox is configured (up to the user) this can be either "the absolute minimum for browsing and New Identity to work" or "also enable the Circuit Display".

Even when the Circuit Display is enabled, Tor Browser only sees circuit/stream information for the circuits/streams it created. If you are scared of the firefox process knowing the IP of your Guard or Bridge(s), people shouldn't enable the Circuit Display, when using the Linux sandbox.

Can't New Identity work without the ControlPort, by just changing the socks credentials?

Firefox knowing what the guard is seems like a very bad idea. Wouldn't it be prudent to assume that actors like the FBI can access "metadata" like who was connected to what guard when, at least for some guards and users if not all of us?

As nice as the Tor Button circuit display is, I think it really needs to be in a different application. Expecting users to be able to make an informed decision about whether to allow Firefox to identify their guard seems reckless.

Is it possible to make stock Tor Browser only need newnym, as in TAILS?
Then it's as easy as instaling a filter for the control port without having to recompile Tor Browser.
Even better still if Tor Browser could drop privileges itself, e.g. by using a builtin filter and somehow making it harder for shellcode to load the unfiltered library(zero out the address to dlopen once browser is done starting?), or if Tor control port only had newnym enabled by default, or came with one control port for dangerous stuff and one that doesn't need protected(and Tor Browser used the latter).

Basically, there are tons of solutions with various tradeoffs. Are any being considered?

It depends?

There's no technical reason why this would be impossible (I ran Tor Browser against a filtered control port for a while before working on the sandboxing stuff), but it would require extra code to get it to play nice if Tor Browser is the app that launches the tor daemon (standard usage).

As far as I know, no one is working on such a thing in a context other than "when sandboxed". was "likely" used to target visitors of a dark web child pornography site, Motherboard has found

In other words, Vice is once again doing their job as a controlled opposition to put the awakening masses back to sleep so TPTB can exploit them unsuspected.

Micah Lee (EFF and FOTP) tweeted earlier today at about a possible cyberattack on Riseup, which is an essential part of Tails ecosystem and helps social justice activists and environmentalists all over the world. This may well be related to the exploit just fixed by TBB 6.0.7

More details should be forthcoming from Riseup.

Actually, it is likely being used to target bloggers, journalists, union organizers, social justice organizers, technologists, and political dissidents in various nations including USA.

> i like the exploit! it goes after childpron users!…

> childpron...

... Yadda yadda yadda.

That's always the "official story" as spun by US media.

RU recently incoporated Chinese technology into their own censorship regime. Maybe they are also incorporating US technology? To target the Russian underground? (See the comment just above yours.)

Sheriff Dave Clarke of Milwaukee County is apparently with the Trump transition team and has been mentioned as a possible future FBI Director in the Trump administration. He has repeatedly claimed (in speeches and Op-Eds) that the US is in a state of "civil war" (his words), apparently meaning BLM versus American police. (In fact, BLM is a nonviolent movement opposed to homicide whether committed by police or by some other party.)

It is much more likely that FBI is using NIT to attack journalists covering the protests at Standing Rock, BLM protests, anti-Trump rallies, government corruption, etc., rather than attacking "suspected child pron producers". It is very easy for them to quietly *define* anyone who uses Tor for any reason as a "suspected child pron producer", and to attack them under that assumption. But we who use Tor every day know very well that most people who use Tor every day have nothing to do with any criminal activity--- unless you regard all opposition to some governmental policy somewhere in the world as criminal.

> [FBI NIT malware] goes after childpron users!

That's always the official FBI spin, but the most recent attack on Tor users is more likely related to the Standing Rock protests, BLM protests, and anti-Trump rallies:…
U.S. border agents stopped journalist from entry and took his phones
Andrea Peterson
30 Nov 2016

> Award-winning Canadian photojournalist Ed Ou has had plenty of scary border experiences while reporting from the Middle East for the past decade. But his most disturbing encounter was with U.S. Customs and Border Protection last month, he said. On Oct. 1, customs agents detained Ou for more than six hours and briefly confiscated his mobile phones and other reporting materials before denying him entry to the United States, according to Ou. He was on his way to cover the protest against the Dakota Access Pipeline on behalf of the Canadian Broadcast Corporation.

Imagining that this attack is a response to something in the past few weeks is misunderstanding how the government bureaucracy works. They probably went through months of paperwork and judges and so on to arrive at approval to deploy it.

That's not to say that all of those barriers actually provided appropriate checks-and-balances. But do not underestimate how many barriers they have in place before deploying something like this. :)

Are you happy when a batch of cars has defective airbags since that bug goes after people who use cars to kidnap children? Do you not care about the bug also going after drivers who don't kidnap children?


I don't understand - is updating Tor to this release make the browser susceptible to exploits? Or was the previous version subject to exploit, so the update fixes it?

The update fixes the vulnerability that was present in the earlier versions. Here is more information:……

But I can see why you're confused, given the number of comments that almost seem to suggest the exploit was a good thing, which is really quite frightening actually. It's really sad to see the Tor community starting to buy into the FBI's FUD.


November 30, 2016


Does the exploit need JavaScript to be enable on browser, or can the exploit execute arbitrary JavaScript code that bypass NoScript?

As far as we know, if you had Javascript disabled (including via Noscript), this exploit would not work on you.

There appears to be some confusion about whether the vulnerability could be exploited without Javascript on, that is, whether it is possible to write a different exploit that works even when Javascript is disabled. The last I heard from Dan Veditz was that he thought no, it shouldn't be possible for this particular Firefox bug.

That said, we've also been hearing rumors about bugs in Noscript that would let a website sneak some javascript past Noscript. So it would seem you might be in better shape putting the Tor Browser security slider to high than you are relying just on Noscript.

Yes but be sure to set security slider to high first.
Very few people will have changed settings manually, meaning you'll stand out more if you just change JS and leave everything else on lowsec. This is why Orfox should have a security slider.
Apparently you also have to disable images, which is impossible( and nobody seems to believe that it should be possible, neither at Mozilla nor at Tor Project.

Let's say I'm using the slider at the highest position, does it make a difference if Noscipt blocks the javascript or if I block it straight in the Browser?

Are there cases Noscript (js globbaly diabled) could get tricked into running javascript but browser wouldn't? (it's not about this particular exploit)

Short version; set security slider to high, and goto about:config and if javascript.enabled equals "True", then toggle it to "False".

Long version;
I don't know that but here's what I know.
If there IS a problem and NoScript gets bypassed, you're almost certainly more secure with javascript.enabled toggled off (set to "False" in about:config).

However, you might be less anonymize, because if an attack is found against NoScript and you're one of a very few number of people who manually disabled, your browser is more fingerprintable; see

But if there's an attack that runs javascript past NoScript the javascript itself might do something far more deanonymizing than just saying "this page was viewed or post was written by one of the few people we couldn't attack"; if the attack isn't blocked it might escalate privileges and install permanent malware or send back hardware serial numbers, which will likely deanonymize you far more than being one of the few people immune to attack; there will be only ONE persin with the same exact MAC address/CPU serial number/etc.

If no attack succeeds in breaking NoScript it doesn't matter if you set javascript.enabled to false or not. But NoScript gets vulnerabilities like any software. The less software that you count on working right, the safer you are.

So putting the Tor Browser security slider to high is doing the same technically with javascript as turning javascript off in about:config? Means it turns JS off completely as NoScript is just a whitelist that could get bypassed theoretically? Is this correct?

Thanks in advance.