Tor Browser 15.0.19 is out with Firefox ESR 140.13 security fixes, including flaws with public exploit code. Here’s what changed and why users should update promptly.
Tor Browser 15.0.19 is out with Firefox ESR 140.13 security fixes, including flaws with public exploit code. Here’s what changed and why users should update promptly.
Event date: July 21, 2026
Primary source publish dates: July 21, 2026 (Tor Project), July 21, 2026 (Mozilla)
Tor Browser 15.0.19 was released on July 21, 2026, and on the surface it looks like a routine maintenance update. It is not. The key change is that Tor rebased its stable browser onto Firefox ESR 140.13, pulling in Mozilla security fixes that were disclosed the same day.
Mozilla’s advisory for Firefox ESR 140.13 is rated critical. Two of the listed issues stand out for privacy-conscious users because Mozilla says public exploit code already exists, even though it has not confirmed real-world exploitation. One affects the JavaScript and WebAssembly component, and another is a site-isolation issue in navigation handling. The advisory also includes additional memory-safety fixes that Mozilla says could potentially be abused for arbitrary code execution with enough effort.
For Tor users, the practical takeaway is simple: this is not just another incremental browser refresh. Tor Browser sits at the center of many users’ anti-censorship and anonymity workflows, so lagging behind on upstream Firefox ESR security patches increases risk. Tor’s own changelog for 15.0.19 is short, but that is exactly why the Mozilla advisory matters more than the release size suggests.
Users on desktop should update to Tor Browser 15.0.19, while Android users should move to the build based on GeckoView 140.13.0esr. There is no evidence of active exploitation in the wild as of July 21, 2026, but public exploit code narrows the margin for delay. For a browser used in high-risk environments, prompt patching is the safer default.