Tor Browser 15.0.24 is now available from the Tor Browser download page and also from our distribution directory.
This version includes important security updates to Firefox.
Windows Package Signature Issue
The DigiCert EV code-signing certificate we use to sign Windows installation packages is expired since September 1st and we are currently in the process to renew it. Unfortunately, this process is delayed and not yet complete.
This has caused Windows users trying to install Tor Browser 15.0.21 and 15.0.22 from scratch to receive "bad signature" warnings.
As a temporary work-around, for Windows only we're keeping Tor Browser 15.0.20 (the latest correctly signed version) listed on our download page, relying on automatic updates (which are signed with a different key, not involving this expired certificate) to bring Windows users to the current version.
Users who prefer to download the latest version directly, ignoring the certificate expiration warning, can download it from https://dist.torproject.org/torbrowser/15.0.24/.
New PGP subkey
This release is signed using a new subkey. If you previously used gpg to verify Tor Browser downloads, you may need to refresh the Tor Browser signing key (0xEF6E286DDA85EA2A4BA7DE684E2C6E8793298290) in your local keyring. For more details you can read our page about signature verification, specifically the section "Refreshing the PGP key".
Send us your feedback
If you find a bug or have a suggestion for how we could improve this release, please let us know.
Full changelog
The full changelog since Tor Browser 15.0.23 is:
All Platforms
Updated NoScript to 13.6.35.1984
Updated Tor to 0.4.9.13
Bug tor-browser#45358: Rebase Tor Browser stable onto 140.17.0esr
Bug tor-browser#45366: Backport Security Fixes from Firefox 157
Bug tor-browser#45368: Account for onion aliases in NoScript site parsing
Bug tor-browser#45371: Hook CharacterData/Range insertion sinks for content patches propagation
Windows + macOS + Linux
Updated Firefox to 140.17.0esr
Bug tor-browser#45218: Implement YEC 2026 Takeover for Desktop Stable
Linux
Bug tor-browser#44996: Change the 32-bit linux message to the expired version for the final 15.0 release
Android
Updated GeckoView to 140.17.0esr
Bug tor-browser#45217: Implement YEC 2026 Takeover for Android Stable
Build System
All Platforms
Bug tor-browser-build#41847: Sign all releases using new gpg subkey
macOS
Bug tor-browser-build#41883: Fix sha256sum definition in projects/hfsplus-tools/config
applications
releases