The new version of the Tor Browser 9.0.7 focuses on ensuring anonymity, security, and privacy. The browser channels all traffic exclusively through the Tor network, making it impossible to connect directly via the current system's network connection, which prevents tracing the user's actual IP address (in the event of a browser breach, attackers could access system network parameters; therefore, to completely block potential leaks, products such as Whonix should be used). The Tor Browser builds are prepared for Linux, Windows, macOS, and Android.
The new release updates the components and , which have fixed vulnerabilities. The Tor update addresses a DoS vulnerability that could create excessive CPU load when interacting with directory servers controlled by attackers. In NoScript, a problem that allowed bypassing the 'Safest' protection mode to execute JavaScript code through to the 'data:' URI.
Additionally, Tor Browser developers provide extra protection and automatically disable JavaScript entirely at the 'Safest' setting level by turning off javascript.enabled in about:config. This change does not allow for a whitelist of sites in NoScript for selectively lifting 'Safest' (to revert to the old behavior, the javascript.enabled value can be manually changed). Once developers are confident that NoScript has closed all loopholes for bypassing 'Safest', additional protection may be removed.
Source: opennet.ru
