Software 45010 Published by

Zen Browser released 1.23.2b today, a patch that polishes its new Library hub and repairs genuine data-integrity bugs. It stops unloaded tabs from vanishing when you drag them into a new window, restores accurate download-blocking messages, and fixes session-backup naming that broke outside UTC timezones. The fixes were reported on October 8 and closed within a day or two by creator Mauro V. (@mr-cheffy), highlighting the project's rapid, maintainer-driven pace. Built on Firefox 157.0.1, the patch inherits Mozilla's fixes from MFSA2026-97 and MFSA2026-104, and native builds for Linux, macOS, and Windows are now available.



Zen Browser 1.23.2b fixes real data-loss bugs, rides Firefox 157.0.1

A tiny open-source team shipped three reported fixes in about 72 hours.

Zen Browser released 1.23.2b today. The build is dated 2026-10-09, and it lands squarely in the 1.23 series that introduced the much-discussed Library hub. This isn't a headline drop. Instead it's a patch that cleans up the Library and repairs some genuine data-integrity problems that had surfaced in the preceding days.

The browser is built on Firefox 157.0.1, so it carries Mozilla's fixes from MFSA2026-97 and MFSA2026-104 forward. Two small conveniences also arrive. But the fixes are where the actual substance sits.

Screenshot_from_2025_03_19_09_16_46

The bugs that bothered people

The one that matters most is a tab-loss bug. Move a pile of tabs into a new window, and Zen could quietly delete the ones that had been unloaded from memory. Those tabs don't show up in "Recently closed" either. So you don't even get a recovery path. Someone drags tabs around and suddenly they're gone. Fix #15810, self-assigned by creator Mauro V. (@mr-cheffy), closed on October 9.

Not exactly a minor annoyance. When a browser is your primary workspace, losing work sessions during a routine drag-and-drop is the kind of silent failure that erodes trust fast.

Then there's the download labeling. Every blocked download showed the same message: "This file contains a virus or malware." It didn't matter what Safe Browsing actually said. An "uncommon" file from somewhere like NexusMods got accused of being malware all the same. That's a correctness fix, but it also has a safety angle. If every block looks like a death warning, users either stop paying attention or start panicking over harmless files. Fix #15809, also in PR #15826.

Keep in mind the fix restores Firefox's actual verdict text, so you'll start seeing the meaningful distinctions again: not commonly downloaded, potentially unwanted, and so on.

The third fix is quietly the one affecting the most people. Session backups were named using a UTC date plus a local hour. That means anything past midnight in a non-UTC timezone got stamped with the previous day's date. Older backups then sort as if they were newest. Someone on UTC+5:45 posted an example that makes the failure mode obvious. Cleanup logic could delete your newer backups first. Fix #15806 in PR #15807, closed October 8. Affects anyone west of UTC too, since evening backups land with the next day's date.

Two small additions

On the feature side, not much. You can now open the Library straight from the command palette. That joins the Opt/Alt + Shift + L shortcut added back in 1.23.1b.

You can also right-click the Media tab inside the Library to hide it. It's a small move, but part of a steady pattern. The Library keeps getting more customizable, with right-click options for clearing downloads and history arriving earlier in the series.

Beyond those, the release notes list a grab-bag of repairs. The Library no longer gets stuck after you open and close it quickly. Right-aligned sidebars don't force as much minimum width anymore. HEIC images render in the media tab. Space-assigned bookmarks persist again after a regression. And there's a startup memory leak patched in somewhere in there.

The context you need

To see why 1.23.2b looks the way it does, it helps to watch the three releases that built up to it.

1.23b dropped on October 2. It introduced the Library, added a resizable and hidden sidebar, turned on WebRTC hardware AV1 decoding, and pushed startup performance with lots of tabs open. 1.23.1b came a few days later on October 6, upgrading the base to Firefox 157.0.1 and adding Library filtering plus that keyboard shortcut. Then 1.23.2b on October 9, refining both.

The 1.22 line underneath it all brought cross-device sync across Spaces, folders, and tabs, plus the squircle redesign. So the 1.23 series isn't standing alone. It's layering organizational features on top of infrastructure.

If you're keeping score, you'll notice the Library has become the centerpiece. In just two patch cycles after its debut, it went from a single new hub to something you can filter, shortcut, right-click, and partially disable. Zen clearly sees a unified "everything at once" hub as central to its whole calmer internet pitch. That's a direct nod to the organizational approach Arc made popular.

How fast did they move?

Bugs were reported on October 8. Three were closed within a day or two, with @mr-cheffy personally triaging and merging. That velocity is genuinely notable for an open-source browser funded mostly by sponsorships. The core team is small, and a lot of it runs through one lead developer who still assigns issues to himself and ships the PRs.

At this point, the near-weekly release cadence is more a signature of the project than a surprise. 1.23b, 1.23.1b, 1.23.2b. Then 1.22.3b on September 22, 1.22.2b on September 15. The repo sits around 44,800 stars with roughly 680 open issues and 68 open pull requests, which tells you the tracker moves faster than the queue grows.

A quick aside

Zen has always sold itself on "We care about your experience, not your data." The positioning has tracked a broader fatigue with browsers turning into heavy, ad-laden, AI-injected platforms. Fixing data-loss bugs and restoring accurate security messages is arguably exactly the kind of thing that earns that line credibility. A browser can promise privacy, but it only earns trust when it stops dropping your open tabs.

The security picture

Zen doesn't publish a standalone advisory for this patch. Instead it inherits Mozilla's fixes from the Firefox 157.0.1 base. Within the 1.23 series, that means MFSA2026-97 from the 157.0 build and MFSA2026-104 from the 157.0.1 build both apply to you. No separate CVE list exists for this release, and the notes didn't carry specific enumerations. Check Mozilla's advisory pages if you want per-CVE detail.

Browsers remain one of the top attack surfaces for remote exploitation, so inheriting hardening on schedule matters. Zen rides 157.0.1 cleanly, which is the important part.

What you can download

Native builds ship for Linux (x86-64 and ARM), macOS including Apple Silicon, and Windows (x86-64 and ARM64). All hashes are SHA-256.

The Linux AppImage for x86-64 is 138 MB, with a 124 MB build for ARM. macOS update packages sit around 159 MB, Windows near 120 MB, and the ARM64 Windows package about 105 MB. Installers and delta updates (.zsync files around 243 KB) are also posted, plus source in both zip and tar.gz.

It's a modest, honest patch. Not cheap in effort, even if it isn't the flashiest thing Zen has shipped. The design of the Library and the breadth of its customization options still help it stand apart, though. At the same time, don't expect this release to move the needle on its own. It's doing exactly what a good patch should: taking real problems people reported and closing them before the weekend.

Head here to download Zen 1.23.2b, or check the release notes and documentation if you want the finer print. Issue trackers for the specific fixes live on the Zen Browser GitHub repo, and Mozilla's advisory pages cover the underlying security details.