Tor Browser 15.0.23 is now available from the Tor Browser download page and also from our distribution directory.
This version includes important security updates to Firefox.
Windows Package Signature Issue
The DigiCert EV code-signing certificate we use to sign Windows installation packages is expired since September 1st and we are currently in the process to renew it. Unfortunately, this process is delayed and not yet complete.
This has caused Windows users trying to install Tor Browser 15.0.21 and 15.0.22 from scratch to receive "bad signature" warnings.
As a temporary work-around, for Windows only we're keeping Tor Browser 15.0.20 (the latest correctly signed version) listed on our download page, relying on automatic updates (which are signed with a different key, not involving this expired certificate) to bring Windows users to the current version.
Users who prefer to download the latest version directly, ignoring the certificate expiration warning, can download it from https://dist.torproject.org/torbrowser/15.0.23/.
Send us your feedback
If you find a bug or have a suggestion for how we could improve this release, please let us know.
Full changelog
The full changelog since Tor Browser 15.0.22 is:
All Platforms
Updated NoScript to 13.6.33.1984
Bug tor-browser#45296: (H1) SharedWorker Identity Mismatch allows WebAssembly execution at Safer
Bug tor-browser#45297: (H1) Missing setHTMLUnsafe hook leaves a permanent WebAssembly-capable child realm at Safer
Bug tor-browser#45299: Backport Security Fixes from Firefox 156
Bug tor-browser#45303: Rebase Tor Browser stable onto 140.16.0esr
Bug tor-browser-build#41875: Update relprep.py for the new versions.ini URL
Windows + macOS + Linux
Updated Firefox to 140.16.0esr
Linux
Bug tor-browser#44996: Change the 32-bit linux message to the expired version for the final 15.0 release
Android
Updated GeckoView to 140.16.0esr
Build System
All Platforms
Bug tor-browser-build#41871: Update downloads repository references in relprep templates
applications
releases