SEPTEMBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-45150

MEDIUM · CVSS 6.3 EPSS 0.25% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-15 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

The Zen Browser, based on Firefox, is vulnerable to a security flaw that allows malicious webpages to enter fullscreen mode without a persistent security notification, potentially obscuring the browser's UI and misleading users into believing they are interacting with a legitimate site. This vulnerability can be exploited for phishing attacks and credential theft by spoofing trusted origins. Users and organizations utilizing Zen Browser versions prior to 1.19.13b should prioritize updating to the latest version to mitigate these risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-45150
Severity
MEDIUM
CVSS
6.3
EPSS
0.25%
Firefox

Original NVD Description

Zen is a firefox-based browser. Prior to 1.19.13b, Zen Browser did not provide a persistent, clearly visible security notification when a webpage entered fullscreen mode, allowing an attacker-controlled page to hide the real browser UI and origin information, imitate a trusted website UI, and combine with long-domain URL eliding to spoof a trusted origin for phishing and credential theft. This issue is fixed in version 1.19.13b.