Native onion support in mainstream browsers: what Brave, Firefox, Chrome and Apple actually deliver
Typing a .onion address into your everyday browser sounds like it should just work. It usually does not, and where it does, the safety guarantees are thinner than most people assume. Mainstream onion support is a story of one careful exception, one cautious compromise, and a lot of silence.
Brave's Tor windows: handy, not hardened
Brave has offered Private Windows with Tor since 2018, chaining each connection through three volunteer-run relays before it reaches its destination. Since version 1.44 the feature also supports pluggable transports, or bridges, for users in countries that block the network outright. On the surface, it looks like Tor Browser living inside a tab. The company's own documentation is refreshingly blunt about the limits. Brave notes that these windows are just regular private windows using Tor as a proxy, and that the browser does NOT implement most of the privacy protections found in Tor Browser (official guidance). If your personal safety depends on staying anonymous, Brave tells you to switch. History backs that warning up. In 2022 researchers disclosed CVE-2022-30334, a flaw that leaked .onion URLs from Tor-window sessions through Referer and Origin headers (NVD entry). Brave patched it quickly, but the episode shows the cost of bolting Tor onto an ordinary browser engine.Firefox: compliant at the edges
Firefox will never resolve a .onion name over plain DNS. Since version 45 it has implemented RFC 7686, blocking lookups through the network.dns.blockDotOnion preference so onion requests cannot leak to recursive resolvers (Bugzilla 1228457). That is a quiet but important safeguard. Mozilla went further in subtler ways. Firefox treats .onion addresses as potentially trustworthy origins and handles them correctly inside HTTPS-First mode, both changes upstreamed with heavy involvement from the Tor Project. Still, the browser ships no Tor integration at all. Pointing it at a local SOCKS proxy works only for tinkerers, and the setup inherits none of Tor Browser's fingerprinting defenses.Chrome and Safari: silence by design
Google and Apple have never implemented the Tor protocol, published no plans to do so, and offer no hidden setting that changes the picture. An onion address typed into Chrome or Safari simply fails to load. That failure is arguably correct behavior. RFC 7686, the standard reserving .onion as a special-use domain, says applications that do not implement the Tor protocol should generate an error and should not perform a DNS lookup (RFC 7686). Complying is easy. Caring enough to build real support is the hard part nobody has attempted.The proxy detour you should skip
Where official support ends, gray-market gateways appear. Tor2Web-style proxies and browser extensions promise to open onion sites from any browser, and security writers have spent years explaining why the trade is bad: the gateway terminates your circuit, sees your destination, and can correlate it with your real address. Extensions add malware risk on top of that."While it is technically possible to route other browsers through Tor, doing so exposes you to serious risks of deanonymization and information leakage," the Tor Project cautions.
What Tor Browser actually adds
The differences run deeper than routing. Tor Browser layers defenses that no mainstream engine currently replicates:- Fingerprinting resistance through uniform fonts, window sizes, and spoofed platform traits
- Per-domain circuit isolation so one site cannot link your activity to another
- Script-blocking enforced by default against drive-by attacks
- Signed automatic updates delivered directly by the Tor Project