Junglewise Threat Intelligence

CVE-2026-44659: Zen Browser address bar spoofing via long subdomains

CVE-2026-44659 · Severity: medium · CVSS 4.7 · Published 2026-05-11

Technologies: Zen Browser. Vendors: Zen Browser.

Executive brief

Zen Browser, a web browser based on Firefox, contains a flaw in how it displays website addresses. An attacker can create a website with an extremely long name that causes the browser to hide the real domain and only show a fake, trusted-looking prefix (like 'google.com') in the address bar. This makes it much easier for attackers to trick users into providing login credentials or financial information on fraudulent websites.

Technical details

A UI misrepresentation vulnerability (CWE-451) exists in Zen Browser prior to version 1.19.12b due to improper handling of long hostnames. The address bar truncates long subdomains from the right, which can hide the actual registrable domain (eTLD+1) while leaving an attacker-controlled prefix visible. An attacker can exploit this by crafting a URL with a very long subdomain that mimics a trusted brand. When a user visits the malicious link, the browser displays only the spoofed prefix, misleading the user about the site's true origin. This vulnerability is fixed in version 1.19.12b.

Affected products

  • Zen Browser Zen Browser < 1.19.12b

Timeline

  • 2026-05-08: advisory: GitHub Security Advisory published
  • 2026-05-11: disclosed: CVE published to NVD
  • 2026-05-11: patched: Vulnerability fixed in version 1.19.12b

References

Related threats