Impact
Zen Browser, a Firefox‑based browser, did not provide a persistent, clearly visible security notification when a webpage entered fullscreen mode prior to version 1.19.13b. This omission allowed attacker‑controlled pages to hide the real browser UI and origin information, imitate a trusted website UI, and combine with long‑domain URL eliding to spoof a trusted origin, facilitating phishing and credential theft. The issue aligns with CWE‑451 and is fixed in version 1.19.13b.
Affected Systems
The issue impacts the zen-browser:desktop product on all installations prior to version 1.19.13b. Users of earlier releases must upgrade to 1.19.13b or later to receive the fixed fullscreen notification.
Risk and Exploitability
The CVSS score of 6.3 denotes a moderate severity, and the EPSS score of <1% indicates a low probability of exploitation at this time. This vulnerability is not listed in the CISA KEV catalog. The likely attack vector is that a user visits an attacker‑controlled page that requests fullscreen; with no notification, the user may inadvertently trust the site, enabling phishing. While the attack requires only user interaction, the absence of a visible origin disclosure amplifies the risk of credential theft.
OpenCVE Enrichment