Security vulnerabilities in JavaScript have been used to [deanonymize Tor Browser in the past](https://arstechnica.com/information-technology/2013/08/attackers-wield-firefox-exploit-to-uncloak-anonymous-tor-users/).
This is because, in Tails, *Tor Browser* is confined using *[[!debwiki AppArmor]]* to protect your files from some types of attacks against *Tor Browser*.