Description
Zen is a firefox-based browser. Prior to 1.19.13b, Zen Browser did not provide a persistent, clearly visible security notification when a webpage entered fullscreen mode, allowing an attacker-controlled page to hide the real browser UI and origin information, imitate a trusted website UI, and combine with long-domain URL eliding to spoof a trusted origin for phishing and credential theft. This issue is fixed in version 1.19.13b.
Published: 2026-07-15
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Zen Browser, a Firefox‑based browser, did not provide a persistent, clearly visible security notification when a webpage entered fullscreen mode prior to version 1.19.13b. This omission allowed attacker‑controlled pages to hide the real browser UI and origin information, imitate a trusted website UI, and combine with long‑domain URL eliding to spoof a trusted origin, facilitating phishing and credential theft. The issue aligns with CWE‑451 and is fixed in version 1.19.13b.

Affected Systems

The issue impacts the zen-browser:desktop product on all installations prior to version 1.19.13b. Users of earlier releases must upgrade to 1.19.13b or later to receive the fixed fullscreen notification.

Risk and Exploitability

The CVSS score of 6.3 denotes a moderate severity, and the EPSS score of <1% indicates a low probability of exploitation at this time. This vulnerability is not listed in the CISA KEV catalog. The likely attack vector is that a user visits an attacker‑controlled page that requests fullscreen; with no notification, the user may inadvertently trust the site, enabling phishing. While the attack requires only user interaction, the absence of a visible origin disclosure amplifies the risk of credential theft.

Generated by OpenCVE AI on July 31, 2026 at 03:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Zen Browser version (1.19.13b or newer) to restore the fullscreen security notification and prevent origin spoofing.
  • If an immediate update is not possible, configure site settings or browser policies to block or warn before an untrusted site requests fullscreen.
  • Educate users to verify the presence of the fullscreen notification bar and scrutinize the real origin before submitting credentials.

Generated by OpenCVE AI on July 31, 2026 at 03:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Zen-browser
Zen-browser desktop
Vendors & Products Zen-browser
Zen-browser desktop

Wed, 15 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Description Zen is a firefox-based browser. Prior to 1.19.13b, Zen Browser did not provide a persistent, clearly visible security notification when a webpage entered fullscreen mode, allowing an attacker-controlled page to hide the real browser UI and origin information, imitate a trusted website UI, and combine with long-domain URL eliding to spoof a trusted origin for phishing and credential theft. This issue is fixed in version 1.19.13b.
Title Zen Browser - Missing Fullscreen Security Notification Allows Origin Spoofing
Weaknesses CWE-451
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N'}


Subscriptions

Zen-browser Desktop
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-15T17:44:16.341Z

Reserved: 2026-05-08T20:44:38.964Z

Link: CVE-2026-45150

cve-icon Vulnrichment

Updated: 2026-07-15T17:44:02.028Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T03:30:18Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information