PT-2026-60208 · Unknown · Zen Browser
CVE-2026-45150
·
Published
2026-07-15
·
Updated
2026-07-15
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Zen Browser versions prior to 1.19.13b
Description
The browser fails to provide a persistent and clearly visible security notification when a webpage enters fullscreen mode. This allows an attacker-controlled page to hide the actual browser user interface and origin information, imitate a trusted website interface, and use long-domain URL eliding to spoof a trusted origin, which can lead to phishing and credential theft.
Recommendations
Update Zen Browser to version 1.19.13b.
Exploit
Fix
UI Misrepresentation of Critical Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zen Browser