Address Bar Spoofing in Zen Browser Affecting Zen Technologies
CVE-2026-44659
4.7MEDIUM
What is CVE-2026-44659?
The Zen Browser, a Firefox-based web browser, exhibits a flaw where lengthy subdomains are improperly truncated in the address bar. This allows an attacker to construct long, malicious subdomains that can visually impersonate legitimate brands. Consequently, users may only see the deceptive prefix in the address bar, obscuring the true registrable domain. This misuse of the address bar essentially undermines its role as a security feature, thereby enabling phishing attacks and potential supply chain threats. The issue has been addressed in version 1.19.12b.
Affected Version(s)
desktop < 1.19.12b
