Tails 7.14 and Tor Browser 15.0.24 Bring Firefox 157 Security Fixes
Tails 7.14 was released on September 30, two weeks after Tails 7.13, on the project’s new two-week cycle. It arrives a day after the Tor Browser 15.0.24 release it is built around.
Tails 7.14
| Component | Version |
|---|---|
| Tor Browser | 15.0.24 |
| Tor | 0.4.9.13 |
| Linux kernel | 6.12.111 |
Kernel 6.12.111 is the current 6.12 longterm release, which includes the fixes for September’s four public kernel root exploits.
The only other fix is for the default keyboard input method when starting a session in Korean.
Upgrading: Tails 7.0 or later can upgrade automatically, keeping Persistent Storage. Accept the upgrade prompt after connecting to Tor. Installing a fresh image instead erases Persistent Storage.
Tor Browser 15.0.24
Released on September 29, Tor Browser 15.0.24 moves to Firefox 140.17.0esr with security fixes backported from Firefox 157, plus Tor 0.4.9.13 and NoScript 13.6.35.
Two practical notes from the Tor Project:
- Windows installers: the DigiCert EV code-signing certificate used for Windows packages expired on September 1. As a workaround, the download page lists 15.0.20, the last correctly signed version, and relies on the automatic updater to bring Windows users to 15.0.24. Linux users are unaffected
- New signing subkey: this release is signed with a new subkey, so if you verify downloads with GPG, refresh the Tor Browser signing key first or verification will fail
gpg --auto-key-locate nodefault,wkd --locate-keys torbrowser@torproject.org
gpg --verify tor-browser-linux-x86_64-15.0.24.tar.xz.asc
Our GPG basics guide explains what that verification proves.