In May, the Open Technology Fund commissioned iSEC Partners to study current and future hardening options for the Tor Browser. The report had the following high-level findings and recommendations. The majority of vulnerabilities to date in Firefox were use-after-free, followed closely by general heap corruption. A large portion of the report was also focused on analyzing historical Firefox vulnerability data and other sources of large vulnerability surface for a planned “Security Slider” UI in Tor Browser. The report makes several recommendations along these lines, but a brief distillation can be found on the ticket for the slider.”]
Source: https://blog.torproject.org/isec-partners-conducts-tor-browser-hardening-study