ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
SUBSCRIBE
ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
ZeroSecurity - Information Security News
No Result
View All Result
Home Privacy

Tails OS Developers Warn Users to not use their Operating System

Kyle by Kyle
May 28, 2022
in Privacy
Reading Time: 2 mins read
Tails OS 5.0 zero-day
Share on FacebookShare on Twitter

The developers of the popular Tails OS (operating system) are warning its users to cease use of their tool due to privacy concerns after the discovery of a prototype pollution vulnerability.

“We recommend that you stop using Tails until the release of 5.1 (May 31) if you use Tor Browser for sensitive information (passwords, private messages, personal information, etc.).” The Tails Developers stated in a blog post on May 24.

Tails is short for “The Amnesic Incognito Live System” which is a Debian-based Linux distribution focused on protecting users’ anonymity (e.g. activists and journalists). The main feature of Tails is it allows anyone to circumvent censorship by routing all internet traffic through the Tor network.

This warning was given by the Tails team due to two critical zero-day exploits in the Firefox JavaScript engine. These zero-days are being tracked under CVE codes CVE-2022-1802 and CVE-2022-1529. They were originally used on the first day of the Pwn2Own 2022 Vancouver hacking contest. These exploits were patched by Mozilla two days later.

While the exploits have been patched, the developers are unable to deliver patches for any of the included apps within Tails due to Tails being a live Linux distro. A live Linux Distro is a Linux operating system that runs completely from RAM. This allows you to run a full instance of the operating system (from either CD/DVD or USB) without making changes to your current system.

These vulnerabilities allow attackers to access info from other websites visited while using the Tor Bowser.

“For example, after you visit a malicious website, an attacker controlling this website might access the password or other sensitive information that you send to other websites afterwards during the same Tails session,” the Tails blog post adds.

You might also like

Google’s Controversial Ad Tracking Move Sparks Privacy Concerns

The Hidden Cost of Convenience: How Your Smart Devices Are Mapping Your Life

LinkedIn Hit with €310 Million GDPR Fine Over Data Privacy Violations

What is the Tails OS used for?

The Tails OS is predominantly utilized against online surveillance and prevents third-party tracking from companies such as Google and Facebook.  The operating system also forces all traffic through the Tor network. The Tor network is a powerful anti-surveillance network built around an encrypted peer-to-peer (P2) network which protects users against traffic analysis as well as having the ability to circumvent censorship put into place by governments or your internet service providers.

Tails OS Vulnerability Workaround

The Tails developers explained that the flaws do not affect Tor Browser users on the safest security level because JavaScript is completely disabled with that level while browsing.

Thunderbird which is also packaged with the Tails OS is not impacted as JavaScript is disabled by default.

Additionally, individuals that use Tails to access information that isn’t sensitive via the Tor Browser will be able to use it safely as the security weaknesses don’t break the encryption and privacy of the Tor peer-to-peer network.

“Mozilla is aware of websites exploiting this vulnerability already. This vulnerability will be fixed in Tails 5.1 (May 31), but our team doesn’t have the capacity to publish an emergency release earlier,” the Tails team warned in the blog post.

 

Tags: Tailstor
Previous Post

SharkBot – A New Generation Android Banking Trojan

Next Post

ChromeLoader Attacking Chrome Browsers Worldwide – How to Protect Yourself

Kyle

Kyle

Writer, and editor at ZeroSecurity. Interested in Information Security, the Blockchain, and an overall tech enthusiast. "Formal education will make you a living; self-education will make you a fortune." Contact me here: [email protected]

Recommended For You

Screenshot of Google Chrome's ad tracking

Google’s Controversial Ad Tracking Move Sparks Privacy Concerns

December 23, 2024
Privacy how we are being spied on

The Hidden Cost of Convenience: How Your Smart Devices Are Mapping Your Life

November 15, 2024

LinkedIn Hit with €310 Million GDPR Fine Over Data Privacy Violations

October 27, 2024

Telegram Tightens Policies: Now Cooperating with Law Enforcement

September 23, 2024 - Updated on September 24, 2024

What Happened to the Spy.pet Discord Scrapers?

September 7, 2024 - Updated on January 10, 2025

Google to Delete User Location Data, Bolstering Privacy Measures

June 6, 2024

Related News

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026
KPMG Netherlands Listed as Victim by Nova Ransomware Group

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026
RansomHouse Claims Breach of Key Apple Assembler Luxshare

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026
ZeroSecurity - Information Security News

We cover the latest in technology news, Crypto, Artificial Intelligence, and the threat trends impacting these sectors.

Categories

Piracy

Tutorials

Programming

Malware Analysis

Downloads

  • Contact us
  • Press
  • Writers
  • Privacy Policy
  • Terms of Service

© 2026 ZeroSecurity, All Rights Reserved.

No Result
View All Result
  • Home
  • Security
    • Tools
  • Exploits
  • Data Breaches
  • Malware
  • Privacy
  • Mobile Security
  • Contact Us
    • Press
  • Privacy Policy

© 2026 ZeroSecurity, All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.