Tor Browser update no longer tracks what apps users install

Tor
(Image credit: Tor Project)

After releasing Tor Browser 10.0 last year, the Tor Project has released a new incremental update for its browser that contains fixes for a number of bugs including one that could allow websites to track users based on the apps installed on their devices.

As reported by BleepingComputer, back in May, the fingerprinting firm FingerprintJS released details on a 'scheme flooding' vulnerability that could be exploited to track users across several different browsers based solely on the applications they've installed.

In order to track users, a tracking profile is created for each user by trying to open several application URL handlers and checking if the browser then launches a prompt. For those unfamiliar, these application URL handlers are often used by video conferencing software such as Zoom to launch a meeting after a link is clicked on in a user's browser.

If an application displays a prompt, then it's safe to assume that the software is installed on a user's device. The scheme flooding vulnerability disclosed by FingerprintJS checks these URL handlers in order to create an ID for each user based on the unique configuration of apps installed on their devices.

Preventing unwanted tracking in Tor

The ID created based on a user's installed apps can even be tracked across several different browsers including Google Chrome, Microsoft Edge, Tor Browser, Firefox and Safari.

However, this vulnerability is especially concerning for Tor users since one of the main draws of the anonymous browser is being able to protect one's identity and IP address from being logged by the sites they visit. Since this vulnerability can track users across browsers, it could be used by websites and potentially even law enforcement to track a user's real IP address when they switch to Chrome or any other browser after using Tor.

Thankfully though, the Tor Project has patched this vulnerability with the release of Tor Browser 10.0.18 which fixes the issue by setting the browser's 'network.protocol-handler.external' setting to false. Once updated, the browser won't be able to pass the handling of URLs to external applications and no more application prompts will appear that can be used to track users.

Tor Browser users can protect themselves from this vulnerability by opening the browser's menu, going to Help and selecting About Tor Browser to automatically check for and install any new updates. However, the new update can also be downloaded manually from the Tor Browser download page or the Tor Project's distribution directory.

Via BleepingComputer

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
Home internet connection. A wlan router on desk with notebook in background.
Cloudflare admits security tool is blocking some challenger browsers
A computer being guarded by cybersecurity.
Worrying Windows security issue patched by 7-Zip, so patch now
A finger touching the google chrome icon in the Windows 10 start menu
A new Chrome browser highjacking attack could affect billions of users - here's how to fight it
Woman using credit card whilst sitting at a desk with a laptop and mobile phone in view
Best web browser of 2025
Apple Siri
Update your Apple device now: iOS 18.3.2 fixes a flaw that could be exploited by hackers
An option to add Ambient Music buttons to the iOS 18.4 Control Center.
Apple fixes dangerous zero-day used in attacks against iPhones and iPads
Latest in Software & Services
woman listening to computer
AWS vs Azure: choosing the right platform to maximize your company's investment
Autonomous finance
Quickbooks vs Quicken: what are the main strengths and weaknesses for your business
finance
Quickbooks vs Xero: which is the best for your business?
Group of people meeting
Zoom vs Google Meet: which is the best video conferencing tool for your business?
Fingers typing on a computer keyboard.
Microsoft 365 Personal vs Microsoft 365 Family: are there any real differences?
Person at laptop
Windows 11 vs Windows 365: which is the best choice for businesses?
Latest in News
A super close up image of the Google Gemini app in the Play Store
It's official: Google Assistant will be retired for phones this year, with Gemini taking over
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 16 (game #1147)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 16 (game #378)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 16 (game #644)
Three iPhone 16 handsets on show
Apple could launch an iPhone 17 Ultra this year – but we've heard these rumors before
Super Mario Odyssey
ChatGPT is the ultimate gaming tool - here's 4 ways you can use AI to help with your next playthrough