CVE-2026-45150
Deferred Deferred - Pending Action

Zen Browser Fullscreen UI Spoofing Vulnerability

Vulnerability report for CVE-2026-45150, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-15

Last updated on: 2026-07-15

Assigner: GitHub, Inc.

Description

Zen is a firefox-based browser. Prior to 1.19.13b, Zen Browser did not provide a persistent, clearly visible security notification when a webpage entered fullscreen mode, allowing an attacker-controlled page to hide the real browser UI and origin information, imitate a trusted website UI, and combine with long-domain URL eliding to spoof a trusted origin for phishing and credential theft. This issue is fixed in version 1.19.13b.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-15
Last Modified
2026-07-15
Generated
2026-08-05
AI Q&A
2026-07-16
EPSS Evaluated
2026-08-03
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zen_browser zen_browser to 1.19.13b (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-451 The user interface (UI) does not properly represent critical information to the user, allowing the information - or its source - to be obscured or spoofed. This is often a component in phishing attacks.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-45150 is a vulnerability in Zen Browser versions before 1.19.13b where the browser fails to show a persistent or clearly visible security notification when a webpage enters fullscreen mode. This allows attackers to hide the real browser UI and domain details, making malicious sites appear as trusted ones.

Detection Guidance

This vulnerability is specific to Zen Browser versions up to 1.19.12b and involves a UI spoofing issue during fullscreen mode. Detection requires checking the installed Zen Browser version. Run Zen Browser and navigate to Settings > About to verify the version. If it is 1.19.12b or lower, the system is vulnerable.

Impact Analysis

This vulnerability could trick you into entering sensitive information like passwords or credit card details on fake websites that look real. Since the browser hides the address bar and security indicators in fullscreen mode, you might not notice you're on a malicious site. Attackers can combine this with long-domain spoofing to make the fake site appear legitimate.

Compliance Impact

This vulnerability could lead to unauthorized data collection or breaches, violating GDPR and HIPAA requirements for protecting user data. Organizations using affected Zen Browser versions may face compliance risks due to insufficient security controls.

Mitigation Strategies

Upgrade Zen Browser to version 1.19.13b or later immediately. This version includes the fix for the fullscreen UI spoofing vulnerability. Disable fullscreen mode for untrusted websites until the update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-45150. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart