<?xml version='1.0' encoding='utf-8'?>
<feed xmlns="http://www.w3.org/2005/Atom"><title>Tor Project blog</title><link href="https://blog.torproject.org/" rel="alternate" /><link href="https://blog.torproject.org/feed.xml" rel="self" /><id>urn:uuid:201c3fb3-b4bd-3a4e-85ed-16327d11d7a6</id><updated>2026-08-05T00:00:00Z</updated><author><name>The Tor Project</name></author><subtitle>Official channel for news and updates from the Tor Project</subtitle><entry><title>New Release: Tails 7.10.1</title><link href="https://blog.torproject.org/new-release-tails-7_10_1/" rel="alternate" /><updated>2026-08-05T00:00:00Z</updated><author><name>tails
</name></author><id>urn:uuid:efc678db-c4c3-3fff-949d-c3850347fff9</id><content type="html">
  &lt;article class="blog-post"&gt;
    &lt;picture&gt;
      &lt;source media="(min-width:415px)" srcset="https://blog.torproject.org/new-release-tails-7_10_1/lead.webp" type="image/webp"&gt;
&lt;source srcset="https://blog.torproject.org/new-release-tails-7_10_1/lead_small.webp" type="image/webp"&gt;

      &lt;img class="lead" referrerpolicy="no-referrer" loading="lazy" src="https://blog.torproject.org/new-release-tails-7_10_1/lead.jpg"&gt;
    &lt;/picture&gt;
    &lt;div class="body"&gt;&lt;p&gt;This release is an emergency release to fix critical security vulnerabilities
in the &lt;em&gt;Linux&lt;/em&gt; kernel and the &lt;em&gt;expat&lt;/em&gt; XML library.&lt;/p&gt;
&lt;h2&gt;Changes and updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Update the &lt;em&gt;Linux&lt;/em&gt; kernel to 6.12.100, which fixes &lt;a href="https://www.cve.org/CVERecord?id=CVE-2026-64560"&gt;CVE-2026-64560&lt;/a&gt;, a vulnerability that could allow &lt;em&gt;Tor Browser&lt;/em&gt; in Tails to gain administrator privileges.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For example, if a malicious website that you visit is able to exploit
CVE-2026-64560, they might take full control of your Tails and deanonymize
you.&lt;/p&gt;
&lt;p&gt;This attack is very unlikely but could be performed by a strong attacker, such
as a government or a hacking firm. We are not aware of this attack being used
in practice until now.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Update the &lt;em&gt;expat&lt;/em&gt; XML library to 2.8.2, which fixes &lt;a href="https://security-tracker.debian.org/tracker/DSA-6404-1"&gt;DSA-6404-1&lt;/a&gt;, a set of vulnerabilities that could allow different applications in Tails to gain administrator privileges.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For example, if an attacker tricks you into opening a malicious file in an
application that uses &lt;em&gt;expat&lt;/em&gt; , such as &lt;em&gt;LibreOffice&lt;/em&gt; , &lt;em&gt;Audacity&lt;/em&gt; , or &lt;em&gt;Git&lt;/em&gt;
, they might then use one of these vulnerabilities to take full control of
your Tails and deanonymize you.&lt;/p&gt;
&lt;p&gt;This attack is very unlikely but could be performed by a strong attacker, such
as a government or a hacking firm. We are not aware of this attack being used
in practice until now.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Compress automatic upgrades with &lt;code&gt;zstd&lt;/code&gt; for a faster startup, as we already did for the USB image in &lt;a href="https://tails.net/news/version_7.0/"&gt;Tails 7.0&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Make USB images and automatic upgrades 70 MB smaller by removing unused firmware.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For more details, read our
&lt;a href="https://gitlab.tails.boum.org/tails/tails/-/blob/master/debian/changelog"&gt;changelog&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Get Tails 7.10.1&lt;/h2&gt;
&lt;h3&gt;To upgrade your Tails USB stick and keep your Persistent Storage&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Automatic upgrades are available from Tails 7.0 or later to 7.10.1.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;If you cannot do an automatic upgrade or if Tails fails to start after an automatic upgrade, please try to do a &lt;a href="https://tails.net/doc/upgrade/#manual"&gt;manual upgrade&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;To install Tails 7.10.1 on a new USB stick&lt;/h3&gt;
&lt;p&gt;Follow our &lt;a href="https://tails.net/install/"&gt;installation instructions&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The Persistent Storage on the USB stick will be lost if you install instead of
upgrading.&lt;/p&gt;
&lt;h3&gt;To download only&lt;/h3&gt;
&lt;p&gt;If you don't need installation or upgrade instructions, you can download Tails
7.10.1 directly:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;a href="https://tails.net/install/download/"&gt;For USB sticks (USB image)&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;a href="https://tails.net/install/download-iso/"&gt;For DVDs and virtual machines (ISO image)&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Support and feedback&lt;/h2&gt;
&lt;p&gt;For support and feedback, visit the &lt;a href="https://tails.net/support/"&gt;Support
section&lt;/a&gt; on the Tails website.&lt;/p&gt;

    &lt;/div&gt;
  &lt;div class="categories"&gt;
    &lt;ul&gt;&lt;li&gt;
        &lt;a href="https://blog.torproject.org/category/tails"&gt;
          tails
        &lt;/a&gt;
      &lt;/li&gt;&lt;li&gt;
        &lt;a href="https://blog.torproject.org/category/releases"&gt;
          releases
        &lt;/a&gt;
      &lt;/li&gt;&lt;/ul&gt;
  &lt;/div&gt;
  &lt;/article&gt;
</content></entry><entry><title>Arti 2.5.1 released</title><link href="https://blog.torproject.org/arti_2_5_1_released/" rel="alternate" /><updated>2026-08-04T00:00:00Z</updated><author><name>opara
</name></author><id>urn:uuid:868f6cfb-9093-397f-af5e-189b45f1feae</id><content type="html">
  &lt;article class="blog-post"&gt;
    &lt;picture&gt;
      &lt;source media="(min-width:415px)" srcset="https://blog.torproject.org/arti_2_5_1_released/lead.webp" type="image/webp"&gt;
&lt;source srcset="https://blog.torproject.org/arti_2_5_1_released/lead_small.webp" type="image/webp"&gt;

      &lt;img class="lead" referrerpolicy="no-referrer" loading="lazy" src="https://blog.torproject.org/arti_2_5_1_released/lead.png"&gt;
    &lt;/picture&gt;
    &lt;div class="body"&gt;&lt;p&gt;Arti is our ongoing project to create a next-generation Tor implementation in Rust.
We're happy to announce the latest release, Arti 2.5.1.&lt;/p&gt;
&lt;p&gt;This release consists mostly of internal improvements and bug fixes,
as well as our ongoing development towards using Arti as a relay and as a directory authority.
For onion service hosts,
onion services can now be configured to connect to unix socket addresses.
Arti also now has experimental support for congestion control
and &lt;a href="https://blog.torproject.org/introducing-cgo/"&gt;Counter Galois Onion&lt;/a&gt; cryptography on onion service circuits,
which we hope to make stable soon.&lt;/p&gt;
&lt;p&gt;For full details on what we've done, including API changes,
and for information about many more minor and less-visible changes,
please see the &lt;a href="https://gitlab.torproject.org/tpo/core/arti/-/blob/main/CHANGELOG.md?ref_type=heads#arti-251---3-august-2026"&gt;CHANGELOG&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;For more information on using Arti, see our top-level &lt;a href="https://gitlab.torproject.org/tpo/core/arti/-/blob/main/README.md"&gt;README&lt;/a&gt;,
and the documentation for the &lt;a href="https://gitlab.torproject.org/tpo/core/arti/-/blob/main/crates/arti/README.md"&gt;&lt;code&gt;arti&lt;/code&gt; binary&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Thanks to everybody who's contributed to this release, including
Andrew Kloet, Jérôme Charaoui, hjrgrn, pryty26, ramdoys, and syphyr.&lt;/p&gt;
&lt;p&gt;Also, our deep thanks to our &lt;a href="https://www.torproject.org/about/sponsors/"&gt;sponsors&lt;/a&gt; for funding the development of Arti!&lt;/p&gt;

    &lt;/div&gt;
  &lt;div class="categories"&gt;
    &lt;ul&gt;&lt;li&gt;
        &lt;a href="https://blog.torproject.org/category/announcements"&gt;
          announcements
        &lt;/a&gt;
      &lt;/li&gt;&lt;li&gt;
        &lt;a href="https://blog.torproject.org/category/releases"&gt;
          releases
        &lt;/a&gt;
      &lt;/li&gt;&lt;/ul&gt;
  &lt;/div&gt;
  &lt;/article&gt;
</content></entry><entry><title>Snowflake Volunteer, an Android app to help people bypass censorship</title><link href="https://blog.torproject.org/snowflake-volunteer-standalone-app-to-help-people-bypass-censorship/" rel="alternate" /><updated>2026-08-03T00:00:00Z</updated><author><name>pavel
</name></author><id>urn:uuid:e9b2db19-33b4-3cd3-81c8-7b90647d9523</id><content type="html">
  &lt;article class="blog-post"&gt;
    &lt;picture&gt;
      &lt;source media="(min-width:415px)" srcset="https://blog.torproject.org/snowflake-volunteer-standalone-app-to-help-people-bypass-censorship/lead.webp" type="image/webp"&gt;
&lt;source srcset="https://blog.torproject.org/snowflake-volunteer-standalone-app-to-help-people-bypass-censorship/lead_small.webp" type="image/webp"&gt;

      &lt;img class="lead" referrerpolicy="no-referrer" loading="lazy" src="https://blog.torproject.org/snowflake-volunteer-standalone-app-to-help-people-bypass-censorship/lead.png"&gt;
    &lt;/picture&gt;
    &lt;div class="body"&gt;&lt;p&gt;Bypassing censorship comes down to two challenges: disguising internet traffic from censors while making an open network easy to reach. &lt;a href="https://snowflake.torproject.org"&gt;Snowflake&lt;/a&gt; is particularly effective at tackling both of these challenges. It disguises a user's traffic to look like a video call and routes it through volunteer-run proxies using short-lived connections, making the traffic harder to detect and block.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;That's why it's important to have a large and healthy pool of volunteers always available. To achieve that, Snowflake has to be easy to use and deploy, ideally on the devices and with the services they already use.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Up until this point, volunteers could use browser extensions, a website embed, a command-line tool for desktop, and on Android they can use Orbot's &lt;em&gt;&lt;a href="https://orbot.app/en/kindness/"&gt;Kindness Mode&lt;/a&gt;&lt;/em&gt;. During the first half of 2026, the Snowflake broker saw an average of approximately 146,000 unique volunteer proxy IP addresses checking in each day&lt;sup class="footnote-ref" id="fnref-nested"&gt;&lt;a href="#fn-nested"&gt;1&lt;/a&gt;&lt;/sup&gt;. Roughly a third of those were associated with Orbot's Kindness Mode. Kindness Mode also makes volunteering tangible by showing users how many connections their proxy has supported.&lt;/p&gt;
&lt;p&gt;Seeing how much capacity that feature contributed, &lt;a href="https://www.bloco.io/"&gt;Bloco&lt;/a&gt;, an Android app studio in Portugal became curious if a standalone app, focused just on volunteering proxies, could reach even more helpers. They reached out to Tor's anti-censorship team which had plans to work on a similar project, but had not yet had the capacity to develop it, yet. So, Bloco took on the task of building such an app.&lt;/p&gt;
&lt;p&gt;The motivation grew out of the team's work with &lt;a href="https://ooni.org/"&gt;OONI (Open Observatory of Network Interference)&lt;/a&gt;, where they saw how NGOs and activists rely on anti-censorship tools to stay safe and connected. After discovering how easy it was to volunteer a Snowflake proxy, the team members wanted to contribute their skills and expertise to an open-source project they cared about.&lt;/p&gt;
&lt;h2&gt;A dedicated app for Snowflake volunteers&lt;/h2&gt;
&lt;p&gt;The Bloco team built on the foundations already developed by the &lt;a href="https://guardianproject.info"&gt;Guardian Project&lt;/a&gt; for the mobile Tor ecosystem, including &lt;a href="https://github.com/tladesignz/IPtProxy"&gt;IPtProxy&lt;/a&gt;. It's an easy-to-use library that brings together the tools and ongoing pluggable transport work needed to integrate Tor into mobile apps, making it easier to keep censorship-circumvention technology current and reuse it across new apps.&lt;/p&gt;
&lt;p&gt;With these libraries already in place, that make it easy to build Tor apps for mobile, Bloco was able to focus their effort on:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Making sure the app runs successfully in the background for as long as possible, while using as little battery as possible.&lt;/li&gt;
&lt;li&gt;Getting the user experience right, so everyone understands what the app is for, and can configure it correctly and according to their internet setup and capabilities.&lt;/li&gt;
&lt;li&gt;Keep volunteers motivated by showing statistics of how much they're helping across time.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img src="https://blog.torproject.org/snowflake-volunteer-standalone-app-to-help-people-bypass-censorship/features-overview.png" alt="Image features overview"&gt;&lt;/p&gt;
&lt;p&gt;The result is Snowflake Volunteer, a single-purpose app that gives volunteers control over when and how they contribute. Users can allow it to run in the background, restrict it to unmetered networks such as Wi-Fi, choose to run it only while the device is charging, and set a limit on how many people it can help simultaneously. Once enabled, the app automatically connects with people seeking a Snowflake proxy and helps route their connection to the Tor network.&lt;/p&gt;
&lt;p&gt;After an initial round of testing and feedback with the Tor community, Snowflake Volunteer was launched publicly in April. In May, we saw an average of approximately 1,300 daily unique proxy IP addresses. By June that had risen to approximately 1,700 per day–an increase of 29% in one month. During this initial period, activity reached a high of more than 2,100 daily proxies. This suggests that a dedicated app can bring additional volunteers into the Snowflake community.&lt;/p&gt;
&lt;h2&gt;Become a Snowflake volunteer by downloading Snowflake Volunteer&lt;/h2&gt;
&lt;p&gt;Snowflake Volunteer is available on &lt;a href="https://f-droid.org/en/packages/io.bloco.snowflake/"&gt;F-Droid&lt;/a&gt; and &lt;a href="https://play.google.com/store/apps/details?id=io.bloco.snowflake"&gt;Google Play&lt;/a&gt;. For those who want to tinker with the app, &lt;a href="https://github.com/blocoio/snowflake"&gt;you can also build it from the source code&lt;/a&gt;. Helping people bypass internet censorship &lt;a href="https://blog.torproject.org/fighting-censorship-with-webtunnel/"&gt;takes a global community&lt;/a&gt;. Tell a friend about this new tool or share this post so more people can learn about this app and &lt;a href="https://github.com/blocoio/snowflake/issues/new"&gt;provide feedback&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;We also would like to thank our community of localizers. Thanks to their efforts, the app is already available in 8 languages (Chinese, English, French, German, Japanese, Portuguese, Turkish and Vietnamese). If you want to expand access to Snowflake Volunteer, consider contributing translations into more languages. Localization is how we reach this global community. Learn &lt;a href="https://community.torproject.org/localization/"&gt;more about the process&lt;/a&gt;, and &lt;a href="https://hosted.weblate.org/projects/snowflake-volunteers/"&gt;get started&lt;/a&gt;.&lt;/p&gt;
&lt;div class="footnotes"&gt;
&lt;hr&gt;
&lt;ol&gt;&lt;li id="fn-nested"&gt;&lt;p&gt;We analyzed 180 available daily Snowflake broker reports covering January 1 through June 30, 2026. Snowflake broker statistics are published as aggregated snowflake-stats descriptors through &lt;a href="https://metrics.torproject.org/collector/archive/snowflakes/"&gt;Tor Metrics’ CollecTor archive&lt;/a&gt;&lt;a href="#fnref-nested" class="footnote"&gt;&amp;#8617;&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;

    &lt;/div&gt;
  &lt;/article&gt;
</content></entry><entry><title>New Release: Tails 7.10</title><link href="https://blog.torproject.org/new-release-tails-7_10/" rel="alternate" /><updated>2026-07-23T00:00:00Z</updated><author><name>tails
</name></author><id>urn:uuid:37d4402b-6844-3da0-9756-3f5d5e0139b8</id><content type="html">
  &lt;article class="blog-post"&gt;
    &lt;picture&gt;
      &lt;source media="(min-width:415px)" srcset="https://blog.torproject.org/new-release-tails-7_10/lead.webp" type="image/webp"&gt;
&lt;source srcset="https://blog.torproject.org/new-release-tails-7_10/lead_small.webp" type="image/webp"&gt;

      &lt;img class="lead" referrerpolicy="no-referrer" loading="lazy" src="https://blog.torproject.org/new-release-tails-7_10/lead.jpg"&gt;
    &lt;/picture&gt;
    &lt;div class="body"&gt;&lt;h2&gt;New features&lt;/h2&gt;
&lt;h3&gt;New shutdown procedure&lt;/h3&gt;
&lt;p&gt;Tails now uses the standard shutdown procedure from GNOME.&lt;/p&gt;
&lt;p&gt;The &lt;a href="https://tails.net/doc/first_steps/shutdown/"&gt;standard shutdown&lt;/a&gt; procedure
is a bit slower, but better prevents data loss.&lt;/p&gt;
&lt;p&gt;For example, the &lt;strong&gt;Power Off&lt;/strong&gt; confirmation dialog informs you if an
application needs to be closed or an open document needs to be saved before
shutting down.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://tails.net/doc/first_steps/shutdown/power_off_with_inhibitor.png"&gt;&lt;img src="https://tails.net/doc/first_steps/shutdown/power_off_with_inhibitor.png" alt=""&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Even without confirming or saving the open documents, Tails will shut down
after 60 seconds.&lt;/p&gt;
&lt;p&gt;You can still use the faster &lt;a href="https://tails.net/doc/first_steps/shutdown/#emergency"&gt;emergency
shutdown&lt;/a&gt; as before.&lt;/p&gt;
&lt;h3&gt;&lt;em&gt;Celluloid&lt;/em&gt; video player&lt;/h3&gt;
&lt;p&gt;We replaced &lt;em&gt;GNOME Videos&lt;/em&gt; with &lt;em&gt;Celluloid&lt;/em&gt; , a more modern and reliable video
player.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://tails.net/news/version_7.10/celluloid.png"&gt;&lt;img src="https://tails.net/news/version_7.10/celluloid.png" alt=""&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;For added security, &lt;em&gt;Celluloid&lt;/em&gt; cannot access the network. You can either:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Open online videos, like MP4 and AVI files, in &lt;em&gt;Tor Browser&lt;/em&gt;.&lt;/li&gt;
&lt;li&gt;Open online streaming addresses, like IPTV and HLS addresses, in &lt;em&gt;VLC&lt;/em&gt; , installed as &lt;a href="https://tails.net/doc/persistent_storage/additional_software/"&gt;additional software&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;em&gt;Celluloid&lt;/em&gt; doesn't work on some computer from 2011 or earlier.&lt;/p&gt;
&lt;p&gt;You can use &lt;em&gt;VLC&lt;/em&gt; instead, installed as &lt;a href="https://tails.net/doc/persistent_storage/additional_software/"&gt;additional
software&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Changes and updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Update &lt;em&gt;Tor Browser&lt;/em&gt; to &lt;a href="https://blog.torproject.org/new-release-tor-browser-15019/"&gt;15.0.19&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Update some firmware packages. This improves support for newer hardware: graphics, Wi-Fi, and so on.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For more details, read our
&lt;a href="https://gitlab.tails.boum.org/tails/tails/-/blob/master/debian/changelog"&gt;changelog&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Get Tails 7.10&lt;/h2&gt;
&lt;h3&gt;To upgrade your Tails USB stick and keep your Persistent Storage&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Automatic upgrades are available from Tails 7.0 or later to 7.10.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;If you cannot do an automatic upgrade or if Tails fails to start after an automatic upgrade, please try to do a &lt;a href="https://tails.net/doc/upgrade/#manual"&gt;manual upgrade&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;To install Tails 7.10 on a new USB stick&lt;/h3&gt;
&lt;p&gt;Follow our &lt;a href="https://tails.net/install/"&gt;installation instructions&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The Persistent Storage on the USB stick will be lost if you install instead of
upgrading.&lt;/p&gt;
&lt;h3&gt;To download only&lt;/h3&gt;
&lt;p&gt;If you don't need installation or upgrade instructions, you can download Tails
7.10 directly:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;a href="https://tails.net/install/download/"&gt;For USB sticks (USB image)&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;a href="https://tails.net/install/download-iso/"&gt;For DVDs and virtual machines (ISO image)&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Support and feedback&lt;/h2&gt;
&lt;p&gt;For support and feedback, visit the &lt;a href="https://tails.net/support/"&gt;Support
section&lt;/a&gt; on the Tails website.&lt;/p&gt;

    &lt;/div&gt;
  &lt;div class="categories"&gt;
    &lt;ul&gt;&lt;li&gt;
        &lt;a href="https://blog.torproject.org/category/tails"&gt;
          tails
        &lt;/a&gt;
      &lt;/li&gt;&lt;li&gt;
        &lt;a href="https://blog.torproject.org/category/releases"&gt;
          releases
        &lt;/a&gt;
      &lt;/li&gt;&lt;/ul&gt;
  &lt;/div&gt;
  &lt;/article&gt;
</content></entry><entry><title>New Alpha Release: Tor Browser 16.0a9</title><link href="https://blog.torproject.org/new-alpha-release-tor-browser-160a9/" rel="alternate" /><updated>2026-07-23T00:00:00Z</updated><author><name>morgan
</name></author><id>urn:uuid:19ddd2dc-a73e-3386-9097-2a307b5d9c3e</id><content type="html">
  &lt;article class="blog-post"&gt;
    &lt;picture&gt;
      &lt;source media="(min-width:415px)" srcset="https://blog.torproject.org/new-alpha-release-tor-browser-160a9/lead.webp" type="image/webp"&gt;
&lt;source srcset="https://blog.torproject.org/new-alpha-release-tor-browser-160a9/lead_small.webp" type="image/webp"&gt;

      &lt;img class="lead" referrerpolicy="no-referrer" loading="lazy" src="https://blog.torproject.org/new-alpha-release-tor-browser-160a9/lead.png"&gt;
    &lt;/picture&gt;
    &lt;div class="body"&gt;&lt;p&gt;Tor Browser 16.0a9 is now available from the &lt;a href="https://www.torproject.org/download/alpha/"&gt;Tor Browser download page&lt;/a&gt; and also from our &lt;a href="https://www.torproject.org/dist/torbrowser/16.0a9/"&gt;distribution directory&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This version includes important &lt;a href="https://www.mozilla.org/en-US/security/advisories/"&gt;security updates&lt;/a&gt; to Firefox.&lt;/p&gt;
&lt;p&gt;⚠️ &lt;strong&gt;Reminder&lt;/strong&gt;: The Tor Browser Alpha release-channel is for &lt;a href="https://community.torproject.org/user-research/become-tester/"&gt;testing only&lt;/a&gt;. As such, Tor Browser Alpha is not intended for general use because it is more likely to include bugs affecting usability, security, and privacy.&lt;/p&gt;
&lt;p&gt;Moreover, Tor Browser Alphas are now based on Firefox's betas. Please read more about this important change in the &lt;a href="https://blog.torproject.org/future-of-tor-browser-alpha/"&gt;Future of Tor Browser Alpha&lt;/a&gt; blog post.&lt;/p&gt;
&lt;p&gt;If you are an at-risk user, require strong anonymity, or just want a reliably-working browser, please stick with the &lt;a href="https://www.torproject.org/download/"&gt;stable release channel&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;It's ESR transition season again!&lt;/h2&gt;
&lt;p&gt;Well actually, it has been ESR transition season throughout this entire release cycle! As described in the aforementioned &lt;a href="https://blog.torproject.org/future-of-tor-browser-alpha/"&gt;Future of Tor Browser Alpha&lt;/a&gt; blog post, we have been incrementally rebasing our Alpha channel on Firefox betas since December of last year. As a result, we now stand before you with Tor Browser 16.0a9 which is based on Firefox ESR 153.&lt;/p&gt;
&lt;p&gt;We will continue rebasing Tor Browser 17.0 Alpha branches on Firefox betas throughout the remainder of the Tor Browser 16.0 release cycle. However, new feature-work for now must be put on hold for a few reasons:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;We must focus our attention on resolving our Bugzilla Audit issues to ensure the features we have inherited from upstream comply Tor Browser's &lt;a href="https://gitlab.torproject.org/tpo/applications/wiki/-/wikis/Design-Documents/Tor-Browser-Design-Doc"&gt;threat model&lt;/a&gt; and to patch any changes which do not.&lt;/li&gt;
&lt;li&gt;Feature work targeting 16.0 stable would need to be cherry-pick'd onto our 17.0 Alpha branches to ensure we don't lose any work. The more invasive a feature patch is, the harder it will be to port to newer versions. This would also be a potentially error-prone process and there is some risk we would lose patches along the way.&lt;/li&gt;
&lt;li&gt;We need to finish stabilizing as soon as possible as we have hard external deadlines which cannot be moved: the end-of-life of Firefox ESR 140 on October 13th and the Google Play Minimum Target API Level requirement on November 1st&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Challenges and Triumphs&lt;/h2&gt;
&lt;h3&gt;💍 Sharing the Load&lt;/h3&gt;
&lt;p&gt;Rebasing the hundreds of Tor Browser patches onto newer versions of Firefox is a challenging task. It is like maintaining the structural stability of sand-castle at high-tide with the waves crashing all around you.&lt;/p&gt;
&lt;p&gt;As such, it quickly become clear early in this new process that we would need to do something if we wanted to avoid burning out the few developers typically involved in this work. To mitigate this, we shared the knowledge internally and spread the work out across all eight members of the team. This way, each developer was only responsible for at most two or three rebases throughout the entire release cycle.&lt;/p&gt;
&lt;h3&gt;🎨 UI Code Churn&lt;/h3&gt;
&lt;p&gt;Over the past year, Firefox has developed and integrated two major changes to the UI in Firefox: a &lt;a href="https://blog.mozilla.org/en/firefox/firefox-settings/"&gt;redesign&lt;/a&gt; of about:preferences in Firefox Desktop and a &lt;a href="https://www.androidsage.com/2026/02/24/firefox-browser-updated-with-new-ui-and-material-3-expressive-hint/"&gt;migration&lt;/a&gt; from Material 2 to Material 3 in Firefox Android.&lt;/p&gt;
&lt;p&gt;Adapting to these types of changes to the frontend are typically rather time-consuming for us, as many (if not the majority) of our patches modify Firefox's UI in some way. For example, we have an entire preferences page on Tor Browser desktop dedicated to configuring how the browser connects to the Tor Network. On Android, we similarly have various additions to the menus, configuration options, and custom UI.&lt;/p&gt;
&lt;p&gt;Whenever Mozilla modifies their design systems and Firefox's user interface, we necessarily have to adapt our own custom additions to match. Otherwise, our Tor Browser-specific UI elements would look completely out of place and potentially confuse users (as well as simply looking unprofessional). Therefore, each of these upstream changes requires collaboration with the Tor Project's UX team to update our features' designs and of course development time to implement.&lt;/p&gt;
&lt;p&gt;In addition to the time-cost associated with the extra engineering and UX collaboration, very often our old patches simply do not apply cleanly due to the amount of code which has changed. For example, the about:preferences changes on Firefox Desktop are essentially a complete re-write which means we also have to completely re-write our own settings changes without regressing in functionality.&lt;/p&gt;
&lt;p&gt;On the plus side, one benefit of our new processes is that we have been able to spread out this work over the entire release cycle. In the past way of doing things, we would have discovered all UX elements which needed to be fixed, updated our designs, and re-implemented in the course of a few months during the old ESR transition season. Under this new way of working, we have been able to incrementally fix things throughout the development cycle.&lt;/p&gt;
&lt;p&gt;The benefits of working this way does not just apply to UX of course. It is much easier to find regressions across the entire stack when rebasing between one major Firefox version at a time instead of across 12 or 13. It is also &lt;em&gt;much&lt;/em&gt; easier for developers to fix individual regressions one at a time compared to diagnosing, disentangling, and fixing multiple bugs concurrently (divide et impera!).&lt;/p&gt;
&lt;h3&gt;⚙️ Pending Google Target API Level Requirements&lt;/h3&gt;
&lt;p&gt;Every year, Google requires new Android app releases to target an updated minimum API level. This means, we would not be able to upload new versions of Tor Browser Stable past a certain date (usually August 1st with an extension to November 1st typically possible) without first updating the app to support the new minimum target API level. Fortunately, we inherit most of the required changes from Mozilla when rebasing to the next major ESR.&lt;/p&gt;
&lt;p&gt;However, this requirement does impose a hard deadline for the absolute latest we can responsibly stabilize Tor Browser Alpha and promote it to Stable. We've been fortunate in the past few years to make the deadline with a few days to spare (October 28th for Tor Browser 15, October 22nd for Tor Browser 14, etc). Given how far ahead of the curve we are this year, we are hoping to release about a month earlier in September (fingers crossed!).&lt;/p&gt;
&lt;h3&gt;🤖 Android APKs too big&lt;/h3&gt;
&lt;p&gt;The Google Play Store has a strict size limit of about 100 megabytes for Android applications. New functionality added to Firefox Android over the past year means a larger application which results in new headaches for Tor Browser developers. This release cycle was no exception to this rule and we have had to get &lt;em&gt;creative&lt;/em&gt; with our size reductions.&lt;/p&gt;
&lt;p&gt;In the past, we have been able reduce our package size though various methods including:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/work_items/41500"&gt;Using custom size-reducing compiler flags&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/work_items/-41407"&gt;Compiling multiple pluggable-transports into a single unified binary to de-duplicate shared dependencies&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/work_items/42386"&gt;Removing unused Firefox assets from the build&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/work_items/42669"&gt;Replacing unused (but still linked) libraries with no-op stubs&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;and &lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/work_items/42607"&gt;countless other methods over there years&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Our most recent effort has been the most invasive yet! For some background, the Firefox application consists of (among other things): various shared libraries, the Firefox executable, a library known as 'xul' which contains most of Firefox's natively compiled functionality, and finally a file known as &lt;code&gt;omni.ja&lt;/code&gt;. This &lt;code&gt;omni.ja&lt;/code&gt; file is a &lt;code&gt;zip&lt;/code&gt; archive which contains the JavaScript, HTML, images, and other assets used in Firefox.&lt;/p&gt;
&lt;p&gt;This time around, to reduce the size of our Android package we have&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/work_items/45086"&gt;changed how this archive is compressed&lt;/a&gt;. We modified the Firefox build system to compress this archive with &lt;code&gt;xz&lt;/code&gt; and we modified Firefox itself to decompress this archive at runtime. This work did require a few iterations to get right. In the end, we got back about 3 megabytes with these changes and got us once again under Google's imposed size budget.&lt;/p&gt;
&lt;h3&gt;📉 Even Less Telemetry&lt;/h3&gt;
&lt;p&gt;Over the years, we have worked to incrementally remove dependencies from Tor Browser Android as part of the aforementioned size reduction work. We of course inherit most of these dependencies from Firefox Android and unfortunately some of them can be labeled as 'trackers'. While we do disable telemetry by default at runtime, the code which implements it remains in the codebase.&lt;/p&gt;
&lt;p&gt;We're happy to report that as of Tor Browser 16.0a8, are down to only 1 'tracker' library in the Tor Browser Android codebase: &lt;code&gt;Mozilla Telemetry&lt;/code&gt;. Again, this telemetry &lt;em&gt;is&lt;/em&gt; disabled at runtime, but this is one more unused dependency which we can &lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/work_items/41295"&gt;hopefully remove in the future&lt;/a&gt; (and maybe get some more bytes back!).&lt;/p&gt;
&lt;h2&gt;Current Status&lt;/h2&gt;
&lt;p&gt;We have:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;incrementally rebased Tor Browser and Tor Browser for Android to Firefox ESR 153 from Firefox ESR 140&lt;/li&gt;
&lt;li&gt;updated the build systems with the latest dependencies and fixed a few reproducibility issues&lt;/li&gt;
&lt;li&gt;triaged &lt;em&gt;most&lt;/em&gt; of the upstream changes from the past year and flagged over 250 issues for further review (triaging of Firefox 153 is in progress)&lt;/li&gt;
&lt;li&gt;resolved about half of these triaged issues&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For the remainder of this release cycle, we will be focusing on auditing these issues and fixing bugs until the 16.0 alpha series is ready to become Tor Browser Stable 16.0. We are optimistically targeting a September release, which would put us one month ahead of schedule compared to last year.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;h3&gt;🦊 Firefox Branding&lt;/h3&gt;
&lt;p&gt;In some places in the browser there may be Firefox branding (e.g. logos, cute little foxes, etc) instead of Tor Browser branding. We're currently tracking one known instance in &lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/work_items/44998"&gt;tor-browser#44998&lt;/a&gt;. If you discover any other instances lurking about, please &lt;a href="https://support.torproject.org/misc/bug-or-feedback/"&gt;open an issue&lt;/a&gt;!&lt;/p&gt;
&lt;h3&gt;🌐 All websites marked 'insecure' on Tor Browser Android&lt;/h3&gt;
&lt;p&gt;Currently, the identity block in the URL bar on Tor Browser Android will always report insecure (e.g. a shield icon with a slash through it). For now, you can tap this icon and verify the certificate manually. This issue is being tracked in &lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/work_items/45115"&gt;tor-browser#45115&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Send us your feedback&lt;/h2&gt;
&lt;p&gt;Now is a great time to &lt;a href="https://blog.torproject.org/vounteer-as-an-alpha-tester/"&gt;become an alpha tester&lt;/a&gt;! If you find a bug or have a suggestion for how we could improve this release, &lt;a href="https://support.torproject.org/misc/bug-or-feedback/"&gt;please let us know&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Full changelog&lt;/h2&gt;
&lt;p&gt;The &lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/raw/main/projects/browser/Bundle-Data/Docs-TBB/ChangeLog.txt"&gt;full changelog&lt;/a&gt; since Tor Browser 16.0a8 is:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;All Platforms&lt;ul&gt;
&lt;li&gt;Updated NoScript to 13.6.30.90201984&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/43819"&gt;Bug tor-browser#43819&lt;/a&gt;: Show custom security level on android&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/44748"&gt;Bug tor-browser#44748&lt;/a&gt;: Revert Funding the Commons Implementations&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/44811"&gt;Bug tor-browser#44811&lt;/a&gt;: Remove the lock on pdfjs.disable.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45101"&gt;Bug tor-browser#45101&lt;/a&gt;: Rebase Tor Browser onto 153.0esr&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45131"&gt;Bug tor-browser#45131&lt;/a&gt;: Security level is using an unsafe getBoolPref&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/issues/41831"&gt;Bug tor-browser-build#41831&lt;/a&gt;: Update libevent to 2.1.13&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Windows + macOS + Linux&lt;ul&gt;
&lt;li&gt;Updated Firefox to 153.0esr&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/44439"&gt;Bug tor-browser#44439&lt;/a&gt;: Remove translate action from urlbar&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/44883"&gt;Bug tor-browser#44883&lt;/a&gt;: Remove urlbar quick action for labs&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45029"&gt;Bug tor-browser#45029&lt;/a&gt;: Convert connection status settings to new design and config approach&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45055"&gt;Bug tor-browser#45055&lt;/a&gt;: Rename --color-gray-05 to --color-gray-0&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45081"&gt;Bug tor-browser#45081&lt;/a&gt;: Use the new "Acorn" icons on desktop&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45110"&gt;Bug tor-browser#45110&lt;/a&gt;: Disable the settings redesign until ready for us&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45112"&gt;Bug tor-browser#45112&lt;/a&gt;: Missing CSS border tokens in 153&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45132"&gt;Bug tor-browser#45132&lt;/a&gt;: nsAppFileLocationProvider.cpp: use of undeclared identifier 'XRE_EXECUTABLE_FILE'&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/issues/41800"&gt;Bug tor-browser-build#41800&lt;/a&gt;: Create a script that adapts the Tor Browser manual HTMLs to work in Tor Browser&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;macOS&lt;ul&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45108"&gt;Bug tor-browser#45108&lt;/a&gt;: Artifact generation fails due to missing .DS_Store in the branding directories&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Android&lt;ul&gt;
&lt;li&gt;Updated GeckoView to 153.0esr&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/43820"&gt;Bug tor-browser#43820&lt;/a&gt;: Use SecurityLevel integration on android&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/44157"&gt;Bug tor-browser#44157&lt;/a&gt;: Remove secret setting toggle for Tab Management Redesign&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45045"&gt;Bug tor-browser#45045&lt;/a&gt;: Remove moz asset in Downloads screen&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45103"&gt;Bug tor-browser#45103&lt;/a&gt;: Disable broken "tab management"&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45109"&gt;Bug tor-browser#45109&lt;/a&gt;: No value passed for parameter 'jsEnabled'&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45118"&gt;Bug tor-browser#45118&lt;/a&gt;: Audit and disable Mozilla VPN promo&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45130"&gt;Bug tor-browser#45130&lt;/a&gt;: Clean up TorHomePage padding&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Build System&lt;ul&gt;
&lt;li&gt;All Platforms&lt;ul&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/issues/41838"&gt;Bug tor-browser-build#41838&lt;/a&gt;: Update personal_access_tokens URL in tools/fetch_changelogs.py&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Windows + Linux + Android&lt;ul&gt;
&lt;li&gt;Updated Go to 1.26.5&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Windows&lt;ul&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/issues/41819"&gt;Bug tor-browser-build#41819&lt;/a&gt;: Fix windows-rs URL in projects/firefox/config&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;

    &lt;/div&gt;
  &lt;div class="categories"&gt;
    &lt;ul&gt;&lt;li&gt;
        &lt;a href="https://blog.torproject.org/category/applications"&gt;
          applications
        &lt;/a&gt;
      &lt;/li&gt;&lt;li&gt;
        &lt;a href="https://blog.torproject.org/category/releases"&gt;
          releases
        &lt;/a&gt;
      &lt;/li&gt;&lt;/ul&gt;
  &lt;/div&gt;
  &lt;/article&gt;
</content></entry><entry><title>New Release: Tor Browser 15.0.19</title><link href="https://blog.torproject.org/new-release-tor-browser-15019/" rel="alternate" /><updated>2026-07-21T00:00:00Z</updated><author><name>ma1
</name></author><id>urn:uuid:8b4a7c7b-1acf-3ca7-b34f-0470d585349c</id><content type="html">
  &lt;article class="blog-post"&gt;
    &lt;picture&gt;
      &lt;source media="(min-width:415px)" srcset="https://blog.torproject.org/new-release-tor-browser-15019/lead.webp" type="image/webp"&gt;
&lt;source srcset="https://blog.torproject.org/new-release-tor-browser-15019/lead_small.webp" type="image/webp"&gt;

      &lt;img class="lead" referrerpolicy="no-referrer" loading="lazy" src="https://blog.torproject.org/new-release-tor-browser-15019/lead.png"&gt;
    &lt;/picture&gt;
    &lt;div class="body"&gt;&lt;p&gt;Tor Browser 15.0.19 is now available from the &lt;a href="https://www.torproject.org/download/"&gt;Tor Browser download page&lt;/a&gt; and also from our &lt;a href="https://www.torproject.org/dist/torbrowser/15.0.19/"&gt;distribution directory&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This version includes important &lt;a href="https://www.mozilla.org/en-US/security/advisories/"&gt;security updates&lt;/a&gt; to Firefox.&lt;/p&gt;
&lt;h2&gt;Send us your feedback&lt;/h2&gt;
&lt;p&gt;If you find a bug or have a suggestion for how we could improve this release, &lt;a href="https://support.torproject.org/misc/bug-or-feedback/"&gt;please let us know&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Full changelog&lt;/h2&gt;
&lt;p&gt;The &lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/raw/maint-15.0/projects/browser/Bundle-Data/Docs-TBB/ChangeLog.txt"&gt;full changelog&lt;/a&gt; since Tor Browser 15.0.18 is:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;All Platforms&lt;ul&gt;
&lt;li&gt;Updated NoScript to 13.6.31.1984&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/44748"&gt;Bug tor-browser#44748&lt;/a&gt;: Revert Funding the Commons Implementations&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45117"&gt;Bug tor-browser#45117&lt;/a&gt;: Rebase Tor Browser stable onto 140.13.0esr&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45124"&gt;Bug tor-browser#45124&lt;/a&gt;: Backport Security Fixes from Firefox 153&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Windows + macOS + Linux&lt;ul&gt;
&lt;li&gt;Updated Firefox to 140.13.0esr&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Android&lt;ul&gt;
&lt;li&gt;Updated GeckoView to 140.13.0esr&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Build System&lt;ul&gt;
&lt;li&gt;All Platforms&lt;ul&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/issues/41838"&gt;Bug tor-browser-build#41838&lt;/a&gt;: Update personal_access_tokens URL in tools/fetch_changelogs.py&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Windows&lt;ul&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/issues/41819"&gt;Bug tor-browser-build#41819&lt;/a&gt;: Fix windows-rs URL in projects/firefox/config&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;

    &lt;/div&gt;
  &lt;div class="categories"&gt;
    &lt;ul&gt;&lt;li&gt;
        &lt;a href="https://blog.torproject.org/category/applications"&gt;
          applications
        &lt;/a&gt;
      &lt;/li&gt;&lt;li&gt;
        &lt;a href="https://blog.torproject.org/category/releases"&gt;
          releases
        &lt;/a&gt;
      &lt;/li&gt;&lt;/ul&gt;
  &lt;/div&gt;
  &lt;/article&gt;
</content></entry><entry><title>New Release: Tor Browser 15.0.18</title><link href="https://blog.torproject.org/new-release-tor-browser-15018/" rel="alternate" /><updated>2026-07-14T00:00:00Z</updated><author><name>ma1
</name></author><id>urn:uuid:8984558e-ff2a-329d-9746-9be61769165b</id><content type="html">
  &lt;article class="blog-post"&gt;
    &lt;picture&gt;
      &lt;source media="(min-width:415px)" srcset="https://blog.torproject.org/new-release-tor-browser-15018/lead.webp" type="image/webp"&gt;
&lt;source srcset="https://blog.torproject.org/new-release-tor-browser-15018/lead_small.webp" type="image/webp"&gt;

      &lt;img class="lead" referrerpolicy="no-referrer" loading="lazy" src="https://blog.torproject.org/new-release-tor-browser-15018/lead.png"&gt;
    &lt;/picture&gt;
    &lt;div class="body"&gt;&lt;p&gt;Tor Browser 15.0.18 is now available from the &lt;a href="https://www.torproject.org/download/"&gt;Tor Browser download page&lt;/a&gt; and also from our &lt;a href="https://www.torproject.org/dist/torbrowser/15.0.18/"&gt;distribution directory&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This version includes important &lt;a href="https://www.mozilla.org/en-US/security/advisories/"&gt;security updates&lt;/a&gt; to Firefox.&lt;/p&gt;
&lt;h2&gt;Send us your feedback&lt;/h2&gt;
&lt;p&gt;If you find a bug or have a suggestion for how we could improve this release, &lt;a href="https://support.torproject.org/misc/bug-or-feedback/"&gt;please let us know&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Full changelog&lt;/h2&gt;
&lt;p&gt;The &lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/raw/maint-15.0/projects/browser/Bundle-Data/Docs-TBB/ChangeLog.txt"&gt;full changelog&lt;/a&gt; since Tor Browser 15.0.17 is:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;All Platforms&lt;ul&gt;
&lt;li&gt;Updated NoScript to 13.6.30.1984&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45111"&gt;Bug tor-browser#45111&lt;/a&gt;: Cherry-pick latest firefox/esr140 commits on 140.12.0esr&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Build System&lt;ul&gt;
&lt;li&gt;All Platforms&lt;ul&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/issues/41821"&gt;Bug tor-browser-build#41821&lt;/a&gt;: Update gpg subkeys for boklm&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Windows + Linux + Android&lt;ul&gt;
&lt;li&gt;Updated Go to 1.25.12&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;

    &lt;/div&gt;
  &lt;div class="categories"&gt;
    &lt;ul&gt;&lt;li&gt;
        &lt;a href="https://blog.torproject.org/category/applications"&gt;
          applications
        &lt;/a&gt;
      &lt;/li&gt;&lt;li&gt;
        &lt;a href="https://blog.torproject.org/category/releases"&gt;
          releases
        &lt;/a&gt;
      &lt;/li&gt;&lt;/ul&gt;
  &lt;/div&gt;
  &lt;/article&gt;
</content></entry><entry><title>New Alpha Release: Tor Browser 16.0a8</title><link href="https://blog.torproject.org/new-alpha-release-tor-browser-160a8/" rel="alternate" /><updated>2026-07-02T00:00:00Z</updated><author><name>ma1
</name></author><id>urn:uuid:e9500787-3810-3d3d-bd4d-59eb2df60de7</id><content type="html">
  &lt;article class="blog-post"&gt;
    &lt;picture&gt;
      &lt;source media="(min-width:415px)" srcset="https://blog.torproject.org/new-alpha-release-tor-browser-160a8/lead.webp" type="image/webp"&gt;
&lt;source srcset="https://blog.torproject.org/new-alpha-release-tor-browser-160a8/lead_small.webp" type="image/webp"&gt;

      &lt;img class="lead" referrerpolicy="no-referrer" loading="lazy" src="https://blog.torproject.org/new-alpha-release-tor-browser-160a8/lead.png"&gt;
    &lt;/picture&gt;
    &lt;div class="body"&gt;&lt;p&gt;Tor Browser 16.0a8 is now available from the &lt;a href="https://www.torproject.org/download/alpha/"&gt;Tor Browser download page&lt;/a&gt; and also from our &lt;a href="https://www.torproject.org/dist/torbrowser/16.0a8/"&gt;distribution directory&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This version includes important &lt;a href="https://www.mozilla.org/en-US/security/advisories/"&gt;security updates&lt;/a&gt; to Firefox.&lt;/p&gt;
&lt;p&gt;⚠️ &lt;strong&gt;Reminder&lt;/strong&gt;: The Tor Browser Alpha release-channel is for &lt;a href="https://community.torproject.org/user-research/become-tester/"&gt;testing only&lt;/a&gt;. As such, Tor Browser Alpha is not intended for general use because it is more likely to include bugs affecting usability, security, and privacy.&lt;/p&gt;
&lt;p&gt;Moreover, Tor Browser Alphas are now based on Firefox's betas. Please read more about this important change in the &lt;a href="https://blog.torproject.org/future-of-tor-browser-alpha/"&gt;Future of Tor Browser Alpha&lt;/a&gt; blog post.&lt;/p&gt;
&lt;p&gt;If you are an at-risk user, require strong anonymity, or just want a reliably-working browser, please stick with the &lt;a href="https://www.torproject.org/download/"&gt;stable release channel&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Send us your feedback&lt;/h2&gt;
&lt;p&gt;If you find a bug or have a suggestion for how we could improve this release, &lt;a href="https://support.torproject.org/misc/bug-or-feedback/"&gt;please let us know&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Full changelog&lt;/h2&gt;
&lt;p&gt;The &lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/raw/main/projects/browser/Bundle-Data/Docs-TBB/ChangeLog.txt"&gt;full changelog&lt;/a&gt; since Tor Browser 16.0a7 is:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;All Platforms&lt;ul&gt;
&lt;li&gt;Updated NoScript to 13.6.25.90301984&lt;/li&gt;
&lt;li&gt;Updated Tor to 0.4.9.11&lt;/li&gt;
&lt;li&gt;Updated OpenSSL to 3.5.7&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/44857"&gt;Bug tor-browser#44857&lt;/a&gt;: Drop &lt;code&gt;browser.display.use_system_colors&lt;/code&gt; from our preference list&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/44896"&gt;Bug tor-browser#44896&lt;/a&gt;: Review Mozilla 2030929: Remove unused pref privacy.partition.network_state&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45018"&gt;Bug tor-browser#45018&lt;/a&gt;: resistfingerprinting not available in appearance.mjs in 152&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45019"&gt;Bug tor-browser#45019&lt;/a&gt;: ReportBrokenSite startup error in 152&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45047"&gt;Bug tor-browser#45047&lt;/a&gt;: Cross-site oracle via worklet rejection error in Safer Mode&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45072"&gt;Bug tor-browser#45072&lt;/a&gt;: Disable XSLT already for 16.0&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Windows + macOS + Linux&lt;ul&gt;
&lt;li&gt;Updated Firefox to 152.0a1&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/44528"&gt;Bug tor-browser#44528&lt;/a&gt;: Make sure desktop IP Protection is disabled on desktop&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/44795"&gt;Bug tor-browser#44795&lt;/a&gt;: Revert BB 27604 patch as not needed anymore&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/44844"&gt;Bug tor-browser#44844&lt;/a&gt;: Use new urlbar CSS variables&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/44888"&gt;Bug tor-browser#44888&lt;/a&gt;: Use &lt;code&gt;--button-opacity-disabled&lt;/code&gt; for disabled styling.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/44955"&gt;Bug tor-browser#44955&lt;/a&gt;: Use &lt;code&gt;context-fill&lt;/code&gt; for &lt;code&gt;about-wordmark.svg&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/44956"&gt;Bug tor-browser#44956&lt;/a&gt;: Switch colours in letterboxing setting icons to match the tab-alignment icons&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45016"&gt;Bug tor-browser#45016&lt;/a&gt;: Several errors about EngineProcess.sys.mjs in 152&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45017"&gt;Bug tor-browser#45017&lt;/a&gt;: Wrong letterboxing background in 152&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45037"&gt;Bug tor-browser#45037&lt;/a&gt;: Potential runtime errors in the search service when changing JS status&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45043"&gt;Bug tor-browser#45043&lt;/a&gt;: Re-add missing changes to settings after 151/152 rebase&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45083"&gt;Bug tor-browser#45083&lt;/a&gt;: Error in about:preferences due to ipprotection missing&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;macOS&lt;ul&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/44728"&gt;Bug tor-browser#44728&lt;/a&gt;: Bundled fonts are broken on macOS when the GPU process is enabled&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Linux&lt;ul&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/@ libfontconfig.so.1/-/issues/45048"&gt;Bug @ libfontconfig.so.1#45048&lt;/a&gt;: Backport Bugzilla 2041887: Crash in after users upgraded to fontconfig 2.18.0 [tor-browser]&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Android&lt;ul&gt;
&lt;li&gt;Updated GeckoView to 152.0a1&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/43856"&gt;Bug tor-browser#43856&lt;/a&gt;: Fix onBackPressed() deprecation&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/44091"&gt;Bug tor-browser#44091&lt;/a&gt;: Add frequent regions to tor connection assist for android&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/44175"&gt;Bug tor-browser#44175&lt;/a&gt;: Remove all default browser functionality (Android)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/44769"&gt;Bug tor-browser#44769&lt;/a&gt;: TBA crash screen has firefox asset as well as a "Send crash report" button&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45052"&gt;Bug tor-browser#45052&lt;/a&gt;: Initialise Tor modules on android in the same order as desktop&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Build System&lt;ul&gt;
&lt;li&gt;All Platforms&lt;ul&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/issues/41802"&gt;Bug tor-browser-build#41802&lt;/a&gt;: Remove the tor daemon requirement for signing&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/issues/41809"&gt;Bug tor-browser-build#41809&lt;/a&gt;: Update toolchains for Firefox 152&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/issues/41813"&gt;Bug tor-browser-build#41813&lt;/a&gt;: Disable build artifacts in &lt;code&gt;make generate_gradle_dependencies_list-geckoview&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/issues/41821"&gt;Bug tor-browser-build#41821&lt;/a&gt;: Update gpg subkeys for boklm&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/issues/41823"&gt;Bug tor-browser-build#41823&lt;/a&gt;: Add versions information to the toolchain list update&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/issues/41827"&gt;Bug tor-browser-build#41827&lt;/a&gt;: Update morgan's keychain with renewed key&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Windows + Linux + Android&lt;ul&gt;
&lt;li&gt;Updated Go to 1.26.4&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Windows&lt;ul&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/issues/41810"&gt;Bug tor-browser-build#41810&lt;/a&gt;: Define GetAddrInfoExCancel on mingw&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Android&lt;ul&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45086"&gt;Bug tor-browser#45086&lt;/a&gt;: Compress omni.ja with xz on Android&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/issues/41830"&gt;Bug tor-browser-build#41830&lt;/a&gt;: Update the browser project to change omni.ja.xz&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;

    &lt;/div&gt;
  &lt;div class="categories"&gt;
    &lt;ul&gt;&lt;li&gt;
        &lt;a href="https://blog.torproject.org/category/applications"&gt;
          applications
        &lt;/a&gt;
      &lt;/li&gt;&lt;li&gt;
        &lt;a href="https://blog.torproject.org/category/releases"&gt;
          releases
        &lt;/a&gt;
      &lt;/li&gt;&lt;/ul&gt;
  &lt;/div&gt;
  &lt;/article&gt;
</content></entry><entry><title>New Release: Tails 7.9.1</title><link href="https://blog.torproject.org/new-release-tails-7_9_1/" rel="alternate" /><updated>2026-07-01T00:00:00Z</updated><author><name>tails
</name></author><id>urn:uuid:ac55db71-31e8-31f7-8107-7aac5257550a</id><content type="html">
  &lt;article class="blog-post"&gt;
    &lt;picture&gt;
      &lt;source media="(min-width:415px)" srcset="https://blog.torproject.org/new-release-tails-7_9_1/lead.webp" type="image/webp"&gt;
&lt;source srcset="https://blog.torproject.org/new-release-tails-7_9_1/lead_small.webp" type="image/webp"&gt;

      &lt;img class="lead" referrerpolicy="no-referrer" loading="lazy" src="https://blog.torproject.org/new-release-tails-7_9_1/lead.jpg"&gt;
    &lt;/picture&gt;
    &lt;div class="body"&gt;&lt;h2&gt;Changes and updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Update &lt;em&gt;Tor Browser&lt;/em&gt; to &lt;a href="https://blog.torproject.org/new-release-tor-browser-15017/"&gt;15.0.17&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Update the &lt;em&gt;Tor&lt;/em&gt; client to 0.4.9.11.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Update the &lt;em&gt;Linux&lt;/em&gt; kernel to 6.12.94, which fixes
&lt;a href="https://www.cve.org/CVERecord?id=CVE-2026-43503"&gt;CVE-2026-43503&lt;/a&gt; (&lt;em&gt;DirtyClone&lt;/em&gt;) and
&lt;a href="https://www.cve.org/CVERecord?id=CVE-2026-46331"&gt;CVE-2026-46331&lt;/a&gt; (&lt;em&gt;PACKET_EDIT_MEME&lt;/em&gt;), vulnerabilities that could allow an application in Tails to gain administration privileges.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For example, if an attacker was able to exploit other unknown security
vulnerabilities in an application included in Tails, they might then use
CVE-2026-46331 to take full control of your Tails and deanonymize you.&lt;/p&gt;
&lt;p&gt;This attack is unlikely, but could be performed by a strong attacker, such as
a government or a hacking firm. We are not aware of this vulnerability being
used in practice until now.&lt;/p&gt;
&lt;h2&gt;Fixed problems&lt;/h2&gt;
&lt;p&gt;For more details, read our
&lt;a href="https://gitlab.tails.boum.org/tails/tails/-/blob/master/debian/changelog"&gt;changelog&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Get Tails 7.9.1&lt;/h2&gt;
&lt;h3&gt;To upgrade your Tails USB stick and keep your Persistent Storage&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Automatic upgrades are available from Tails 7.0 or later to 7.9.1.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;If you cannot do an automatic upgrade or if Tails fails to start after an automatic upgrade, please try to do a &lt;a href="https://tails.net/doc/upgrade/#manual"&gt;manual upgrade&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;To install Tails 7.9.1 on a new USB stick&lt;/h3&gt;
&lt;p&gt;Follow our &lt;a href="https://tails.net/install/"&gt;installation instructions&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The Persistent Storage on the USB stick will be lost if you install instead of
upgrading.&lt;/p&gt;
&lt;h3&gt;To download only&lt;/h3&gt;
&lt;p&gt;If you don't need installation or upgrade instructions, you can download Tails
7.9.1 directly:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;a href="https://tails.net/install/download/"&gt;For USB sticks (USB image)&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;a href="https://tails.net/install/download-iso/"&gt;For DVDs and virtual machines (ISO image)&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Support and feedback&lt;/h2&gt;
&lt;p&gt;For support and feedback, visit the &lt;a href="https://tails.net/support/"&gt;Support
section&lt;/a&gt; on the Tails website.&lt;/p&gt;

    &lt;/div&gt;
  &lt;div class="categories"&gt;
    &lt;ul&gt;&lt;li&gt;
        &lt;a href="https://blog.torproject.org/category/tails"&gt;
          tails
        &lt;/a&gt;
      &lt;/li&gt;&lt;li&gt;
        &lt;a href="https://blog.torproject.org/category/releases"&gt;
          releases
        &lt;/a&gt;
      &lt;/li&gt;&lt;/ul&gt;
  &lt;/div&gt;
  &lt;/article&gt;
</content></entry><entry><title>Arti 2.5.0 released: Stable Counter Galois Onion</title><link href="https://blog.torproject.org/arti_2_5_0_released/" rel="alternate" /><updated>2026-06-30T00:00:00Z</updated><author><name>cve
</name></author><id>urn:uuid:365faef9-9c7c-3ab5-91d5-d6ae1c14cc3a</id><content type="html">
  &lt;article class="blog-post"&gt;
    &lt;picture&gt;
      &lt;source media="(min-width:415px)" srcset="https://blog.torproject.org/arti_2_5_0_released/lead.webp" type="image/webp"&gt;
&lt;source srcset="https://blog.torproject.org/arti_2_5_0_released/lead_small.webp" type="image/webp"&gt;

      &lt;img class="lead" referrerpolicy="no-referrer" loading="lazy" src="https://blog.torproject.org/arti_2_5_0_released/lead.png"&gt;
    &lt;/picture&gt;
    &lt;div class="body"&gt;&lt;p&gt;Arti is our ongoing project to create a next-generation Tor implementation in
Rust.  We're happy to announce the latest release, Arti 2.5.0.&lt;/p&gt;
&lt;p&gt;This release marks &lt;a href="https://blog.torproject.org/introducing-cgo/"&gt;Counter Galois Onion&lt;/a&gt; as a stable feature and includes it in
full feature builds.  Likewise, &lt;a href="https://blog.torproject.org/congestion-contrl-047/"&gt;Congestion Control&lt;/a&gt; is now enabled in default
builds of Arti, increasing the overall speed without any further configuration.&lt;/p&gt;
&lt;p&gt;Unfortunately, this release also comes with the disclosure of two medium-severity
DoS security issues, &lt;a href="https://gitlab.torproject.org/tpo/core/arti/-/work_items/2566"&gt;TROVE-2026-024&lt;/a&gt; as well as &lt;a href="https://gitlab.torproject.org/tpo/core/arti/-/work_items/2601"&gt;TROVE-2026-027&lt;/a&gt;, whose fixes
are of course included within the release.&lt;/p&gt;
&lt;p&gt;Additionally, this release continues our ongoing development towards using
Arti as a relay and as a directory authority.&lt;/p&gt;
&lt;p&gt;Another noteworthy change is that we've increased our minimum supported Rust
version to Rust 1.91, released in October 2025.&lt;/p&gt;
&lt;p&gt;Of course, this release also contains a number of bugfixes, cleanups, and
improvements throughout various parts of the code base.&lt;/p&gt;
&lt;p&gt;For full details on what we've done, including API changes,
and for information about many more minor and less-visible changes,
please see the &lt;a href="https://gitlab.torproject.org/tpo/core/arti/-/blob/main/CHANGELOG.md?ref_type=heads#arti-250--30-june-2026"&gt;CHANGELOG&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;For more information on using Arti, see our top-level &lt;a href="https://gitlab.torproject.org/tpo/core/arti/-/blob/main/README.md"&gt;README&lt;/a&gt;,
and the documentation for the &lt;a href="https://gitlab.torproject.org/tpo/core/arti/-/blob/main/crates/arti/README.md"&gt;&lt;code&gt;arti&lt;/code&gt; binary&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Thanks to everybody who's contributed to this release, including
5225225, Neel Chauhan, hjrgrn, moumenalaoui, pryty26.&lt;/p&gt;
&lt;p&gt;Also, our deep thanks to our &lt;a href="https://www.torproject.org/about/sponsors/"&gt;sponsors&lt;/a&gt; for funding the development of Arti!&lt;/p&gt;

    &lt;/div&gt;
  &lt;div class="categories"&gt;
    &lt;ul&gt;&lt;li&gt;
        &lt;a href="https://blog.torproject.org/category/announcements"&gt;
          announcements
        &lt;/a&gt;
      &lt;/li&gt;&lt;li&gt;
        &lt;a href="https://blog.torproject.org/category/releases"&gt;
          releases
        &lt;/a&gt;
      &lt;/li&gt;&lt;/ul&gt;
  &lt;/div&gt;
  &lt;/article&gt;
</content></entry></feed>