Zen Browser 1.21.15b drops today with Firefox 154, cross-platform backups, and 60+ security fixes
Zen Browser 1.21.15b is live on the stable channel today. The update upgrades its engine to Firefox 154.0, rolls in several long-requested UX improvements, and ships with a massive security patch that addresses over sixty CVEs. If you're running a forked Firefox browser, you should update right away.
Built on Mozilla's codebase with a "calmer internet" tagline, Zen has quietly become one of the most popular Firefox forks available. The project sits at roughly 44,000 GitHub stars. Its feature set, which includes Spaces for tab management, customizable sidepanels, per-site CSS "Boosts," and Glance Tabs, has convinced plenty of power users to abandon stock Firefox.
What's actually new
The headline change is the engine jump from Firefox 153.0.4 to 154.0. You're getting all of upstream's performance tweaks, new Web APIs, and rendering upgrades baked directly into the Zen fork. No waiting for third-party patches.
The team also finally extended local profile backups to macOS. Before today, that feature was locked to Windows and Linux. You can now restore backups across all three platforms. Migrating your browser state between operating systems just got a lot less painful.
Cookie handling got a meaningful tweak, too. Previously, exempting a site from shutdown cookie clearing would also strip away tracking protection and other restrictions for that same domain. Now you can opt out of cookie wiping without handing trackers a free pass.
Full-page translations now process content inside iframes. Language detection runs automatically on every page load, so you'll be offered translations without hunting for a button. It's a small change, but it removes one of the most tedious friction points when browsing multilingual sites.
There's also a long tail of quiet fixes. macOS users should see better battery life with vibrancy effects enabled. WebRTC memory leaks on the same platform are gone. Windows users get fixes for the auto-hiding taskbar and taskbar-over-PiP behavior. A hard reload finally clears the favicon cache, which means you stop seeing the old icon after a site redesign.
The project's GitHub stars have been one of the more reliable indicators of its trajectory. It's not uncommon for Firefox forks to stall out after their initial hype, but Zen has stayed on a tight release schedule since March 2024. That kind of consistency is what actually separates a hobby project from a maintained product. Roughly every four days. Some friction remains.
The security situation
This release ships with Mozilla's MFSA2026-74 advisory. Mozilla rates it as high severity. It addresses over sixty CVEs, including sandbox escapes in the Remote Settings client, privilege escalation in the DOM networking stack, use-after-free bugs in WebAssembly and the garbage collector, and site isolation issues in CanvasWebGL.
Dozens of those were tracked internally by Mozilla. Many show clear signs of memory corruption that would take serious effort to exploit. Staying on an older Firefox or Zen version leaves you exposed to actively dangerous flaws. The exact breakdown of reporter credits and component fixes is detailed in the advisory, but the takeaway is straightforward. Update now.
Keep in mind that Zen has two documented issues with this release. Some users are reporting slower password storage performance after a recent rewrite of the password architecture. A subset of people with a primary password enabled are seeing unexpected prompts on launch and page load. It's not catastrophic, but it might warrant a day of testing before you trust the update with your saved logins.
Head here to grab the 1.21.15b update if you haven't already. The official changelog and the full MFSA advisory drop detailed breakdowns of every fixed bug and security patch, so it's worth a quick read if you care about what's actually in your browser.
