#27672 closed defect (duplicate)

User-agent OS info leak

Reported by: time_attacker Owned by: tbb-team
Priority: Immediate Milestone:
Component: Applications/Tor Browser Version:
Severity: Blocker Keywords:
Cc: Actual Points:
Parent ID: Points:
Reviewer: Sponsor:

Description

Tor Browser 8.0 on Linux has user-agent
Mozilla/5.0 (X11; Linux x86_64; rv:60.0) Gecko/20100101 Firefox/60.0

I also suspect Windows/MacOS version is leaked through UA. This behavior can aid fingerprinting or vulnerability exploitation.

Tor Browser 7.x.x and before had one single Windows user-agent even on Linux platforms, only Android (Orfox) had other UA.

Child Tickets

Change History (2)

comment:2 Changed 11 months ago by gk

Resolution: duplicate
Status: newclosed
Note: See TracTickets for help on using tickets.