Impact
Prior to Zen Browser version 1.21.5b, the context‑menu actions "Open link in glance" and "Split link in new tab" erroneously load a page‑controlled link URL with the System principal instead of the page’s originating principal. This bypasses the web‑content scheme restriction that normally blocks file URLs when clicked, allowing a malicious web page to supply a file link that can be opened with System privileges through the context menu. The result is local privilege escalation that permits reading, modifying, or executing arbitrary files on the user’s machine. The weakness is an improper principal assignment (CWE‑266).
Affected Systems
Zen Browser for desktop in all releases earlier than 1.21.5b is affected; versions 1.21.5b and later are not susceptible because the issue has been fixed.
Risk and Exploitability
The EPSS score is less than 1 %, indicating a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. No CVSS score is available, but the single user interaction requirement (right‑click and select the context‑menu action) and the severe impact of System‑level access make the risk significant for unpatched systems. The vulnerability remains a local threat that depends on a malicious web page and user action, rather than an automated attack.
OpenCVE Enrichment