CyberRota Analysis
AI-GeneratedThe Zen Browser, based on Firefox, is vulnerable to a security flaw that allows malicious webpages to enter fullscreen mode without a persistent security notification, potentially obscuring the browser's UI and misleading users into believing they are interacting with a legitimate site. This vulnerability can be exploited for phishing attacks and credential theft by spoofing trusted origins. Users and organizations utilizing Zen Browser versions prior to 1.19.13b should prioritize updating to the latest version to mitigate these risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Zen is a firefox-based browser. Prior to 1.19.13b, Zen Browser did not provide a persistent, clearly visible security notification when a webpage entered fullscreen mode, allowing an attacker-controlled page to hide the real browser UI and origin information, imitate a trusted website UI, and combine with long-domain URL eliding to spoof a trusted origin for phishing and credential theft. This issue is fixed in version 1.19.13b.