Address Bar Spoofing in Zen Browser Affecting Zen Technologies
CVE-2026-44659

4.7MEDIUM

Key Information:

Status
Vendor
CVE Published:
11 May 2026

What is CVE-2026-44659?

The Zen Browser, a Firefox-based web browser, exhibits a flaw where lengthy subdomains are improperly truncated in the address bar. This allows an attacker to construct long, malicious subdomains that can visually impersonate legitimate brands. Consequently, users may only see the deceptive prefix in the address bar, obscuring the true registrable domain. This misuse of the address bar essentially undermines its role as a security feature, thereby enabling phishing attacks and potential supply chain threats. The issue has been addressed in version 1.19.12b.

Affected Version(s)

desktop < 1.19.12b

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.