Tails Linux critical vulnerability allows websites to deanonymize users: emergency patch available
The exploit can be leveraged by state-sponsored attackers or hacking firms.

Image by Cybernews.
- Tails fixed a critical Linux flaw that let malicious websites seize control and deanonymize users.
- Users should upgrade immediately to version 7.10.1; earlier Tails releases remain vulnerable.
- Tor Project says sophisticated attackers could exploit the flaw, but no attacks have been observed.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Tails, a security and anonymity-focused portable Linux distribution that keeps no records of user activity, has fixed a critical kernel vulnerability. Simply visiting a malicious website could deanonymize the user.
Tails, or The Amnesic Incognito Live System, is urging users to upgrade to version 7.10.1 as soon as possible, because previous versions are affected by a critical kernel vulnerability tracked as CVE-2026-64560.
Tor Project warns that it allows Tor Browser to gain administrator privileges on the system. Therefore, a malicious website could take full control of Tails and deanonymize users.
“This attack is very unlikely but could be performed by a strong attacker, such as a government or a hacking firm. We are not aware of this attack being used in practice until now,” the Tor Project said in a blog post.
Users, such as activists or journalists, who try to hide their identities or avoid censorship, prefer to load Tails from a USB stick rather than a storage device – the OS leaves no traces on disk after shutting down. It can, however, store some persistent files on the USB stick itself, such as documents, emails, or additional software. Tor Browser is built in for secure access to the internet.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
First disclosed last week, the bug has been lurking in the Linux kernel since version 5.7, released on May 31st, 2020. The flaw affects Linux’s POSIX CPU timer subsystem, causing a rare race condition to occur in edge cases.
Tails update also fixes other vulnerabilities that could allow different applications in the OS to gain administrator privileges.
“For example, if an attacker tricks you into opening a malicious file in an application that uses expat, such as LibreOffice, Audacity, or Git, they might then use one of these vulnerabilities to take full control of your Tails and deanonymize you,” the advisory warns.
Again, such an attack is very unlikely and can potentially be pulled off against very valuable targets by nation-states or other sophisticated attackers. No exploitation in the wild has been observed.
Tails can be upgraded automatically or manually to preserve the “Persistent Storage” on the USB drive. Reinstalling the OS on the USB stick would wipe the data.