VYPR
Vendor

Zen Browser

Products
3
CVEs
5
Across products
6
Status
Private

Products

3

Recent CVEs

5
  • CVE-2026-41431HigMay 11, 2026
    risk 0.45cvss 8.0epss 0.00

    Zen is a firefox-based browser. Prior to 1.19.9b, Zen Browser ships a Mozilla Application Resource (MAR) updater (org.mozilla.updater) that has had all MAR signature verification stripped from the Firefox codebase it was forked from. The MAR files served to users contain zero…

  • CVE-2026-44659MedMay 11, 2026
    risk 0.31cvss 4.7epss 0.00

    Zen is a firefox-based browser. Prior to 1.19.12b, the ZEN Browser incorrectly truncates long hostnames in the address bar and shows only the attacker-controlled prefix of the subdomain, hiding the actual registrable domain (eTLD+1). As a result, an attacker can craft extremely…

  • CVE-2026-44658LowMay 11, 2026
    risk 0.16cvss 2.4epss 0.00

    Zen is a firefox-based browser. Prior to 1.19.12b, RSS feed URLs entered by the user are validated to http: or https: in promptForFeedUrl, but item links inside the feed are not subject to the same restriction. The provider maps each RSS/Atom item link into item.url, filters…

  • CVE-2026-45150MedJul 15, 2026
    risk 0.00cvss epss 0.00

    Zen is a firefox-based browser. Prior to 1.19.13b, Zen Browser did not provide a persistent, clearly visible security notification when a webpage entered fullscreen mode, allowing an attacker-controlled page to hide the real browser UI and origin information, imitate a trusted…

  • CVE-2026-57501NonJul 9, 2026
    risk 0.00cvss 0.0epss 0.00

    Zen is a firefox-based browser. Prior to 1.21.5b, Zen's glance and split-view context-menu actions, Open link in glance and Split link in new tab, load a page-controlled link URL with the System principal instead of the originating page's principal, allowing a malicious web page…