Executive brief
Zen Browser is a web browser based on Firefox. A security flaw in the browser's "glance" and "split-view" features could allow a malicious website to trick the browser into opening local files with elevated system privileges. While this requires the user to manually right-click a link and select a specific menu option, it could allow an attacker to bypass security restrictions that normally prevent websites from accessing files on your computer.
Technical details
A privilege escalation vulnerability exists in Zen Browser's 'Open link in glance' and 'Split link in new tab' context-menu actions. These features load page-controlled URLs using the System principal instead of the originating page's principal. This flaw allows a malicious web page to bypass standard content-to-file security checks by linking to a 'file://' URL. If a user interacts with the link via the affected context-menu items, the target loads with System privileges. While testing indicated that 'javascript:' and 'chrome://' targets are not affected, the vulnerability allows for the exposure of local files. The issue is resolved in version 1.21.5b.
Affected products
- Zen Browser Zen Browser < 1.21.5b
Timeline
- 2026-07-02: patched: Fixed in version 1.21.5b
- 2026-07-09: disclosed: Advisory published via GitHub and NVD