No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 12 May 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zen-browser
Zen-browser desktop |
|
| Vendors & Products |
Zen-browser
Zen-browser desktop |
Mon, 11 May 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 11 May 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Zen is a firefox-based browser. Prior to 1.19.9b, Zen Browser ships a Mozilla Application Resource (MAR) updater (org.mozilla.updater) that has had all MAR signature verification stripped from the Firefox codebase it was forked from. The MAR files served to users contain zero cryptographic signatures, and the updater binary contains zero cryptographic verification code. This eliminates the defense-in-depth that MAR signing provides. If the update server or GitHub release pipeline is compromised, arbitrary unsigned code can be delivered to all Zen users via the auto-update mechanism. This vulnerability is fixed in 1.19.9b. | |
| Title | Zen Browser MAR updater ships with signature verification removed — unsigned updates accepted | |
| Weaknesses | CWE-347 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-11T18:31:38.146Z
Reserved: 2026-04-20T15:32:33.814Z
Link: CVE-2026-41431
Updated: 2026-05-11T18:31:33.175Z
Status : Received
Published: 2026-05-11T18:16:34.280
Modified: 2026-05-11T19:16:22.897
Link: CVE-2026-41431
No data.
OpenCVE Enrichment
Updated: 2026-05-12T09:22:51Z