Zen Browser 1.21.9b Lands on Firefox 153.0 With a Massive 44-CVE Security Patch
The Firefox fork adds HDR video, EU eIDAS compliance, and multi-PDF merging, while inheriting Mozilla’s largest security advisory in years.
Zen Browser has officially shipped version 1.21.9b. It sits on top of Firefox 153.0 and lands July 25, 2026. If you scroll past the feature list, you’ll notice the real story here. The build absorbs Mozilla’s latest security advisory straight into the release. That advisory addresses 44 CVEs. Many of them are critical sandbox escapes and use-after-free vulnerabilities.
Zen markets itself as a productivity-first Firefox fork. The project has roughly 43,600 GitHub stars and a feature set built around workspaces, compact mode, and split view. But the engine beneath the UI matters more this week. Mozilla dropped its security patch on July 21, and Zen absorbed it four days later. No separate fork-level patching pass. That kind of sync is pretty rare for derivative browsers.
What’s Actually New
HDR video playback now works on Windows, assuming you actually flipped the toggle in Windows Settings → Display first. The PDF sidebar got a native multi-document merge, so you can drag one PDF on top of another and combine them without hunting for an external tool. European enterprise users will notice QWAC and eIDAS compliance. Zen now verifies and displays qualified website authentication certificates. That’s a first for a Firefox fork and it should matter to anyone doing mutual TLS for government work in the EU. The container management UI got a refresh. macOS gets full Globe-F keyboard shortcut support. The video overlay context menu finally behaves properly over embedded players.
The bug fixes cover the usual friction points. Essentials context menu was always disabled. Space Routing external links weren’t routing correctly. Boosts size overrides weren’t sticking across sessions. Nothing earth-shattering, but the kind of nagging issues that compound over time.
One oddity you’ll spot immediately. The release is labeled stable, but the version number carries a beta tag: 1.21.9b. It’s probably just Zen’s naming convention, but it’s worth calling out if you’re used to strict semantic versioning.
The Security Sweep
Mozilla’s MFSA2026-68 advisory is tagged high-impact. Eighteen high-severity CVEs. Twenty-two moderate. Four low. The common thread across several of them is sandbox escapes. Firefox isolates content in separate processes, and a handful of bugs in this batch let attackers break out of that isolation via DOM navigation, WebRTC audio and video, and even the disability access APIs. Use-after-free patterns show up repeatedly. There’s also a cluster of JIT and WebAssembly miscompilations reported by Nebula Security and Amy Burnett at OpenAI. That points to coordinated fuzzing and research. Memory safety issues round out the advisory, hitting Firefox 153, ESR 140.13, and ESR 115.38 all at once.
Zen inherits all of this. Upgrade now and you’re patched. You don’t get a separate Zen-specific CVE list to read through. It’s a clean handoff from upstream.
It’s a solid, if predictable, update. The productivity features are nice, but the real value here is inheriting Mozilla’s security sweep without delay. For a fork that’s already competing with Chromium-based browsers on media fidelity, HDR support closes one gap. QWAC compliance opens another. If you run Firefox forks for privacy or workspace organization, this is a low-friction upgrade. Not cheap in terms of what’s actually new, but the security posture alone justifies clicking install.
You can grab Zen 1.21.9b from the official site or the GitHub releases page. Head here to see the full changelog and download assets. Keep in mind that the underlying Firefox 153 patch is already public, so if you run another Firefox derivative, the timeline is probably similar.
