Tor · Tor Browser · CVE-2021-39246
**Name of the Vulnerable Software and Affected Versions**
Tor Browser versions 10.5.6 and 11.x through 11.0a4
**Description**
The issue allows a correlation attack that can compromise the privacy of visits to v2 onion addresses. Exact timestamps of these onion-service visits are logged locally, and an attacker might be able to compare them to timestamp data collected by the destination server (or collected by a rogue site within the Tor network). This can occur when the `--log` or `--verbose` option is used.
**Recommendations**
For Tor Browser versions 10.5.6 and 11.x through 11.0a4, consider disabling the verbose logging feature to minimize the risk of exploitation. Avoid using the `--log` or `--verbose` option until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.