PT-2026-60208 · Unknown · Zen Browser

CVE-2026-45150

·

Published

2026-07-15

·

Updated

2026-07-15

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Zen Browser versions prior to 1.19.13b
Description The browser fails to provide a persistent and clearly visible security notification when a webpage enters fullscreen mode. This allows an attacker-controlled page to hide the actual browser user interface and origin information, imitate a trusted website interface, and use long-domain URL eliding to spoof a trusted origin, which can lead to phishing and credential theft.
Recommendations Update Zen Browser to version 1.19.13b.

Exploit

Fix

UI Misrepresentation of Critical Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45150
GHSA-VJFV-85QF-V25C

Affected Products

Zen Browser