Batch-Signature Verification Issue in Tor Browser by Tor Project
CVE-2021-38385
7.5HIGH
What is CVE-2021-38385?
A vulnerability in Tor Browser versions before 0.3.5.16, 0.4.5.10, and 0.4.6.7 arises from a flaw in the handling of batch-signature verification in conjunction with single-signature verification. This oversight can result in a remote assertion failure, affecting the overall security posture of the application. Affected users are encouraged to upgrade to the latest versions to mitigate potential risks.
