Junglewise Threat Intelligence

CVE-2026-57501: Zen Browser Privilege Escalation in Glance and Split-View Context Menus

CVE-2026-57501 · Severity: info · CVSS 0 · Published 2026-07-09

Technologies: Zen Browser. Vendors: Zen Browser.

Executive brief

Zen Browser is a web browser based on Firefox. A security flaw in the browser's "glance" and "split-view" features could allow a malicious website to trick the browser into opening local files with elevated system privileges. While this requires the user to manually right-click a link and select a specific menu option, it could allow an attacker to bypass security restrictions that normally prevent websites from accessing files on your computer.

Technical details

A privilege escalation vulnerability exists in Zen Browser's 'Open link in glance' and 'Split link in new tab' context-menu actions. These features load page-controlled URLs using the System principal instead of the originating page's principal. This flaw allows a malicious web page to bypass standard content-to-file security checks by linking to a 'file://' URL. If a user interacts with the link via the affected context-menu items, the target loads with System privileges. While testing indicated that 'javascript:' and 'chrome://' targets are not affected, the vulnerability allows for the exposure of local files. The issue is resolved in version 1.21.5b.

Affected products

  • Zen Browser Zen Browser < 1.21.5b

Timeline

  • 2026-07-02: patched: Fixed in version 1.21.5b
  • 2026-07-09: disclosed: Advisory published via GitHub and NVD

References

Related threats