CVE Explorer
CVE-2026-44659
Zen is a firefox-based browser. Prior to 1.19.12b, the ZEN Browser incorrectly truncates long hostnames in the address bar and shows only the attacker-controlled prefix of the subdomain, hiding the actual registrable domain (eTLD+1). As a result, an attacker can craft extremely long malicious subdomains that visually imitate trusted brands, and the browser will display only the spoofed prefix, misleading users about the actual origin of the site. This directly compromises the URL bar as a securi
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"desktop","vendor":"zen-browser","versions":[{"status":"affected","version":"< 1.19.12b"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:24421e1375c13f7c801a640c53ad2464055168e86cc1bbeb4201185850dc82f7 · sha256:99cb36aa46788db7… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.7,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:24421e1375c13f7c801a640c53ad2464055168e86cc1bbeb4201185850dc82f7 · sha256:99cb36aa46788db7… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-451","description":"CWE-451: User Interface (UI) Misrepresentation of Critical Information","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:24421e1375c13f7c801a640c53ad2464055168e86cc1bbeb4201185850dc82f7 · sha256:99cb36aa46788db7… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"https://github.com/zen-browser/desktop/security/advisories/GHSA-7p2r-fp29-9w69","tags":["x_refsource_CONFIRM"],"url":"https://github.com/zen-browser/desktop/security/advisories/GHSA-7p2r-fp29-9w69"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:24421e1375c13f7c801a640c53ad2464055168e86cc1bbeb4201185850dc82f7 · sha256:99cb36aa46788db7… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.