Medium severity4.3NVD Advisory· Published May 28, 2019· Updated Jun 17, 2026
CVE-2019-12383
CVE-2019-12383
Description
Tor Browser before 8.0.1 has an information exposure vulnerability. It allows remote attackers to detect the browser's UI locale by measuring a button width, even if the user has a "Don't send my language" setting.
Affected products
3cpe:2.3:a:torproject:tor_browser:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:torproject:tor_browser:*:*:*:*:*:*:*:*range: <8.0.1
- (no CPE)range: <8.0.1
- Tor Project/Tor Browserdescription
Patches
Vulnerability mechanics
References
4- gitweb.torproject.org/tor-browser.git/commit/nvdMailing ListPatchThird Party Advisory
- www.securityfocus.com/bid/108484nvdBroken LinkThird Party AdvisoryVDB Entry
- hackerone.com/reports/282748nvdIssue TrackingThird Party Advisory
- trac.torproject.org/projects/tor/ticket/24056nvdVendor Advisory
News mentions
0No linked articles in our index yet.