Skip to content

Tor Changelog

Tor Browser, Tor daemon, and Onion service release summaries. Newest at the top. Each entry links back to the full translation.

Two release channels

  • StableWhat regular users should run, versioned like 15.0.20.
  • AlphaTesting only. It may contain bugs affecting usability, security, and privacy, and is versioned with an a (16.0a10, for example). Do not use it if you need strong anonymity.

Since 16.0a6 (May 2026) the alpha channel has been based on Firefox betas, rebasing in small steps. The beta line it follows became the new Firefox ESR 153 in July, which is why entries from 16.0a9 onward carry esr version numbers again: same line, not a return to the old base. Stable releases almost always carry Firefox or tor daemon security fixes, so install them as they appear. Firefox moved to a two-week release cadence in September 2026 and Tor Browser follows, so stable updates now arrive more often than before.

Tor Browser 16.0a12 (alpha)

2026-09-22 · Upstream announcement

  • AlphaThe alpha channel is for testing only; regular users should stay on the stable channel (15.x).
  • Rebased the Firefox base onto 153.3.0esr (tor-browser#45304), with Android GeckoView following, and backported security fixes from Firefox 156 (tor-browser#45299), the same batch as stable 15.0.23.
  • The bundled tor daemon moves to 0.4.9.12 and NoScript to 13.6.33.90101984. tor 0.4.9.13, released the next day, is not included yet (see the tor daemon changelog).
  • On desktop, onion services using self-signed certificates now show a security exception warning with a button to proceed (tor-browser#42065). WebXR is explicitly disabled (tor-browser#45278), and so is the toolbar share button (tor-browser#45133).
  • The build now passes --disable-proxy-direct-failover (tor-browser#45336), removing the fallback that sends traffic directly when the proxy fails.
  • On Android, the "Passwords" UI is gone (tor-browser#44548), search suggestions are disabled entirely (tor-browser#45269), and about:config opens again (tor-browser#45280).
  • Alpha releases are now signed with a new GPG subkey (tor-browser-build#41846). If you verify download signatures yourself, refresh the Tor Browser developers' key before checking.
  • The Windows installer signing problem is not resolved yet, as the DigiCert EV certificate is still being renewed. Fresh installs of 16.0a11 or 16.0a12 raise a bad signature warning; upstream suggests installing 16.0a10 and letting automatic updates carry it forward.

Tor Browser 15.0.23

2026-09-15 · Upstream announcement

  • StableBoth headline fixes land on the security level itself: a browser set to Safer could still run WebAssembly. If you rely on the security slider to keep scripts and WebAssembly out, update first.
  • One came in through SharedWorker identity matching (tor-browser#45296), the other through a missing setHTMLUnsafe hook that left behind a permanently WebAssembly-capable child realm (tor-browser#45297). Safer is supposed to switch WebAssembly off, and these two let that switch be bypassed.
  • Upstream marks both with (H1). The same marker appeared on the "script execution in Safest mode via data URI navigation" fix in 15.0.4 — both times the security level itself was what got bypassed.
  • The Firefox base moves to 140.16.0esr with security fixes backported from Firefox 156 (tor-browser#45299, tor-browser#45303), and Android GeckoView follows. NoScript updates to 13.6.33.1984.
  • Windows users have a signing problem to know about. The DigiCert EV certificate used to sign the installers expired on 1 September and has not been reissued yet, so fresh installs of 15.0.21 and 15.0.22 raise a bad signature warning. The download page therefore still lists 15.0.20 for Windows and relies on automatic updates to carry people forward; those are signed with a different key and are unaffected. To install the new version directly, take it from the distribution directory and expect an expired-certificate warning along the way.
  • The 32-bit Linux notice switched to the expired-version message again, with the tracking item calling this the final 15.0 release (tor-browser#44996). The 15.0.21 entry cited that same item, 15.0.22 and 15.0.23 shipped anyway, and which build actually ends the line will only be settled once 16.0 stable takes over.

Tor Browser 15.0.22

2026-09-09 · Upstream announcement

  • StableThe release carries exactly one change: the bundled tor daemon moves to 0.4.9.12, a security release covering seven TROVE identifiers that upstream very strongly recommends installing as soon as possible.
  • Several of the issues fixed in 0.4.9.12 matter from the client side — a hostile directory cache could make the browser believe certain relays were unusable, there was a use-after-free when AutomapHostsOnResolve was set, and consensus diffs had no size cap and could be used to exhaust memory. Each one is covered in the tor daemon changelog.
  • The 15.0.21 entry above cites an upstream tracking item calling it the final 15.0 release. 15.0.22 still shipped on the 15.0.x line, carrying this tor security fix.

Tor Browser 16.0a11 (alpha)

2026-09-02 · Upstream announcement

  • AlphaThe alpha channel is for testing only; regular users should stay on the stable channel (15.x).
  • Rebased the Firefox base onto 153.2.0esr (tor-browser#45254), with Android GeckoView following, and backported security fixes from Firefox 155 (tor-browser#45259).
  • Local Network Access (LNA) restrictions are now always on for Android as defence in depth (tor-browser#44155). Pages can no longer reach local network or loopback addresses directly, which closes one route for probing other devices on the same network.
  • TorConnect redirections now go through the parent process (tor-browser#45264), the same fix that shipped in stable 15.0.21.
  • The build now pulls GCC sources from gcc.gnu.org (tor-browser-build#41860), and Go moves to 1.26.8 in the build toolchain.

Tor Browser 15.0.21

2026-09-01 · Upstream announcement

  • StableA small release focused on Firefox security fixes.
  • Rebased the Firefox base onto 140.15.0esr (tor-browser#45253), with Android GeckoView following, and backported security fixes from Firefox 155 (tor-browser#45259).
  • Fixed about:torconnect not appearing when the browser starts outside private browsing mode (tor-browser#45223). TorConnect redirections now go through the parent process (tor-browser#45264).
  • NoScript updated to 13.6.32.1984, OpenSSL to 3.5.8, and Go to 1.25.14 in the build toolchain.
  • Upstream switched the 32-bit Linux notice to the expired-version message, and the tracking item states this is the final 15.0 release (tor-browser#44996). Per the plan announced with 16.0a9, the 16.0 stable series takes over in September, so anyone on 15.x can start preparing to move.

Tor Browser 16.0a10 (alpha)

2026-08-27 · Upstream announcement

  • AlphaThe alpha channel is for testing only; regular users should stay on the stable channel (15.x).
  • New opt-in "Use generic window titles" setting, under Privacy and security → Advanced settings → Protections from third-party applications. With it enabled, every window title simply reads Tor Browser Alpha. Window titles normally track the page's <title> element, and other applications or the OS can read those changes without special permissions, which makes them a side channel for recording browsing history. The feature has been upstreamed, so vanilla Firefox users can set privacy.exposeContentTitleInWindow and privacy.exposeContentTitleInWindow.pbm to false in about:config. The Tor Project had hoped to enable it by default in 16.0, but held off over possible breakage with accessibility software and non-standard desktop environments.
  • The desktop built-in manual has been replaced with the Tor Project's updated support content, baked into the browser. Open it directly at about:manual, or through the "Learn more" links in the UI.
  • The settings page now uses Mozilla's redesigned about:preferences by default, with Tor Browser's own settings (connection, letterboxing, security level) migrated to the new design language.
  • Rebased the Firefox base onto 153.1.0esr (tor-browser#45205) and backported security fixes from Firefox 154 (tor-browser#45219).
  • Disabled locale-based font rules as defence in depth against fingerprinting (tor-browser#44257).
  • Updated NoScript to 13.6.31.90301984 and OpenSSL to 3.5.8.
  • about:torconnect now reports an error when the tor daemon crashes (tor-browser#43570), and bridge settings update when a connection fails (tor-browser#43939).

Tor Browser 15.0.20

2026-08-18 · Upstream announcement

  • StableA small release focused on Firefox security fixes.
  • Rebased the Firefox base onto 140.14.0esr (tor-browser#45204); desktop and Android GeckoView also moved to 140.14.0esr.
  • Backported security fixes from Firefox 154 (tor-browser#45219).
  • Updated libevent to 2.1.13 in the build toolchain (tor-browser-build#41839).
  • Updated Go to 1.25.13 for Windows, Linux, and Android builds.
  • Updated the torbrowser.gpg keyring with a new subkey and a revised expiration date for the main key (tor-browser-build#41850).

Tor Browser 16.0a9 (alpha)

2026-07-23 · Upstream announcement

  • AlphaThe alpha channel is for testing only; regular users should stay on the stable channel (15.x).
  • Major rebase of the Firefox base onto 153.0esr (up from 140.0esr); Android GeckoView also moved to 153.0esr (tor-browser#45101).
  • The Tor Project announced the alpha channel will now track Firefox beta releases and rebase incrementally, instead of jumping a full year of Firefox versions at once, aiming to ship Tor Browser 16.0 stable a month early in September.
  • NoScript updated to 13.6.30.90201984, Go to 1.26.5, and libevent to 2.1.13 in the build toolchain.
  • Only one tracking-related dependency remains, Mozilla Telemetry (disabled by default).
  • Known issues: Firefox branding still appears in some places, and the Android address bar icon currently always shows "insecure" — tap it to verify the certificate manually.

Tor Browser 15.0.19

2026-07-21 · Upstream announcement

  • StableA small release focused on Firefox security fixes, carrying important security updates from Firefox.
  • Rebased the Firefox base onto 140.13.0esr (tor-browser#45117); desktop and Android GeckoView also moved to 140.13.0esr.
  • Backported security fixes from Firefox 153 (tor-browser#45124).
  • NoScript updated to 13.6.31.1984.
  • Reverted the earlier Funding the Commons implementation changes (tor-browser#44748).

Tor Browser 15.0.18

2026-07-14 · Upstream announcement

  • StableA small release focused on Firefox security fixes.
  • The Firefox base stays at 140.12.0esr; rather than rebasing, later fixes were cherry-picked from the firefox/esr140 branch (tor-browser#45111).
  • NoScript updated to 13.6.30.1984, and Go to 1.25.12 in the build toolchain (Windows, Linux, Android).
  • Build process updated boklm's GPG subkey (tor-browser-build#41821).

Tor Browser 16.0a8 (alpha)

2026-07-02 · Upstream announcement

  • AlphaThe alpha channel is for testing only and may contain usability, security, and privacy bugs; regular users should stay on the stable channel (15.x).
  • Important Firefox security update, rebased onto Firefox 152.0a1 (the previous alpha 16.0a7 was on 151.0a1); Android GeckoView also moved to 152.0a1.
  • tor client updated to 0.4.9.11, NoScript to 13.6.25.90301984, OpenSSL to 3.5.7, and Go to 1.26.4 in the build toolchain.
  • Fixed a cross-site oracle vulnerability by rejecting worklets in Safer Mode; XSLT disabled for the 16.0 series.
  • Desktop: disabled IP Protection and fixed letterboxing background rendering plus several regressions after the Firefox 152 rebase. Android: added frequent regions to Tor connection assist, removed default-browser functionality, and switched omni.ja to xz compression.

Tor Browser 15.0.17

2026-06-28 · Upstream announcement

  • StableA small release focused on a tor security update, with no change to the Firefox base.
  • tor client updated to 0.4.9.11.
  • NoScript updated to 13.6.25.1984.
  • Build process updated boklm's GPG subkey and renewed morgan's signing key (tor-browser-build#41821, #41827).

Tor Browser 15.0.16

2026-06-17 · Upstream announcement

  • StableImportant security update to Firefox.
  • Rebased onto Firefox 140.12.0esr (tor-browser#45046), with security fixes backported from Firefox 152 (tor-browser#45054); Android GeckoView also moved to 140.12.0esr.
  • NoScript updated to 13.6.24.1984, fixing a DocStartInjection regression introduced in 13.6.19.902 (tor-browser#45044); OpenSSL updated to 3.5.7.
  • Removed the tor daemon requirement for signing (tor-browser-build#41802), and updated Go to 1.25.11 in the build toolchain.

Tor Browser 15.0.15

2026-06-03 · Upstream announcement

  • StableImportant security update to the tor daemon, plus fixes for some censorship circumvention problems.
  • tor client updated to 0.4.9.9, NoScript updated to 13.6.20.1984.
  • Moat module now supports multiple configured (front, reflector) domain fronting pairs (tor-browser#42436).
  • Fixed a captcha failure on desktop (tor-browser#44997) and notified Linux i686 users that updates have ended (tor-browser#44886).

Tor Browser 16.0a7 (alpha)

2026-06-03 · dist directory

  • AlphaThe alpha channel is for testing only; regular users should stay on the stable channel (15.x). Binaries are published on dist, but the upstream blog has not posted an announcement yet. Now based on Firefox 151.0a1 (the previous alpha 16.0a6 was on 150.0a1).

Earlier Tor Browser versions

Tor Browser 15.0.14, 15.0.13, 16.0a6 (alpha), 15.0.12, 15.0.11, and earlier entries are currently available only in traditional Chinese. English versions will be added as the community translates them.

Past Tor-related translations also live in Updates, including Cure53 completes Tor VPN code audit.