Tor Browser 15.0.23 Ships Security Fixes as Windows Signing Certificate Lapses

Tor Browser 15.0.23 arrives with Firefox security patches, but an expired Windows code-signing certificate means fresh installers carry signature warnings until renewal finishes.

Sep 15, 2026
3 min read
Technobezz
Tor Browser 15.0.23 Ships Security Fixes as Windows Signing Certificate Lapses

Don't Miss the Good Stuff

Get tech news that matters delivered weekly. Join 50,000+ readers.

Tor Browser 15.0.23 is out, and the headline for most users is a batch of security fixes carried over from Firefox. The release is available from the project's download page and its distribution directory. Anyone running an older build should treat this as a maintenance update worth taking, since the changes address flaws rather than adding features.

The catch sits on Windows. DigiCert's EV code-signing certificate for Windows packages expired on September 1, and the renewal has not finished yet. That means people who installed 15.0.21 or 15.0.22 from scratch ran into bad signature warnings. For now the Windows download page still points at 15.0.20, the newest build with a valid signature.

Automatic updates are not affected, because they are signed with a different key that the expired certificate does not touch. Users who grab 15.0.23 directly from dist.torproject.org have to proceed despite a certificate expiration warning. No date has been given for when the renewed certificate will be in place.

Under the hood, the stable browser is now based on Firefox 140.16.0esr, a build that also lands on Windows, macOS and Linux. Android users get the same 140.16.0esr version through GeckoView. NoScript moves to 13.6.33.1984 across every platform.

The security work includes fixes backported from Firefox 156. Listed separately in the changelog are two other flaws: a shared worker identity mismatch that could let WebAssembly run at the Safer security level, and a missing setHTMLUnsafe hook that left a WebAssembly-capable child realm reachable at the same level.

Smaller housekeeping changes ride along. The message shown to 32-bit Linux users now says the version is expired, a change made for the final 15.0 release. The project's relprep.py tooling was updated for a new versions.ini URL, and download repository references in its templates were adjusted. Bug reports and suggestions are being collected through the usual feedback channel.

This lands a week after 15.0.22, which brought security updates to Tor itself and moved the bundled Tor to 0.4.9.12. The quick turnaround fits a broader shift: Firefox moved to a two-week release cadence from September, and Tor Browser and Tails said they would follow the same schedule. Tails 7.12 was the first release on that cadence and shipped Tor Browser 15.0.21.

Separately, an alpha build numbered 16.0a11 is already circulating for testing. The project has also been building a Tor VPN for Android from scratch, work it has described in its own beta notes. Neither of those is the stable channel, and neither is what 15.0.23 delivers.

Share

More in News