Windows application shell
Native ZSEC interface, managed tabs and downloads, exact About information and no reuse of Chrome, Edge or Brave profiles.
Windows Community 0.3 client · Chromium 120+ extension
ZSEC Browser Community 0.3.0 is an unsigned Windows WebView2 client with source and local acceptance evidence. ZSEC Browser Shields 0.4 is the current downloadable Manifest V3 extension.
Release boundary: Shields 0.4 is an unsigned website evaluation package built from draft pull request #5, distinct from the latest formal GitHub prerelease and any Store package. Browser Community 0.3.0 is an unsigned source/local-evidence build at immutable revision 9b60c31, not a public native binary. Keep browser and WebView2 updates enabled.
Windows development build · local acceptance evidence
The Community client has its own executable, branded window, tabs, address bar, Desktop and Start-menu entries, isolated profile and runtime evidence. Microsoft maintains the Evergreen WebView2 Chromium engine; ZSEC maintains the shell and reviewed policy adapter.
Native ZSEC interface, managed tabs and downloads, exact About information and no reuse of Chrome, Edge or Brave profiles.
81 reviewed blocker domains and 21 tracking parameters are deterministically adapted from ZSEC Browser Shields 0.4 data rules.
Site permissions default to deny; certificate errors are cancelled; password autofill, host objects, web messaging, developer tools and automatic download opening are disabled.
The installed executable passed hash, signed-runtime, isolated-profile, HTTPS, tracking-cleanup and reviewed-domain blocking checks without prohibited weakening flags.
The ZSEC executable is not publisher-signed and no ZSEC binary updater or independent sandbox/Site Isolation attestation has shipped. Inspect the immutable Community 0.3.0 source and build documentation. This site does not ask users to bypass SmartScreen for an unsigned artifact.
Downloadable website evaluation package
The downloadable extension makes the protection layer useful now while keeping its permissions, blocking behaviour and complete source open to review.
Configured ad, analytics, fingerprinting and session-replay requests are handled with 38 packaged Manifest V3 rules. No remote browsing-history service is required.
Two top-level navigation rules remove common campaign identifiers such as utm_*, gclid and fbclid without a remote redirect service.
A bounded content script can use visible skip controls and hide configured promoted slots. The site changes frequently, so perfect coverage is not promised.
A local allow rule can recover a broken site without disabling protection everywhere. Paused domains remain visible in extension storage.
ZSEC Browser Shields installs no root certificate, proxies no encrypted traffic, replaces no shopping links and forces no search provider.
Every requested permission maps to a visible feature. Rules, source modules, tests, privacy contract and deterministic packager are public.
Removing configured ads and trackers can reduce exposure and distraction. It cannot guarantee that every site, extension, download or account is safe. Browser and operating-system updates still matter.
Optional · off by default
High-Risk Browsing adds two fixed local Manifest V3 request rules. When both the master protection switch and this profile are on, it blocks top-level plaintext HTTP navigation and third-party scripts, subframes, objects and WebSockets.
Top-level http:// navigation is blocked before the request is sent. HTTPS protects transport, but it does not prove that a site or its content is safe.
Third-party scripts, subframes, objects and WebSockets are blocked. First-party active content, images, media, stylesheets, fonts and fetch/XHR are not blanket-blocked.
The preference stays in browser-local storage. The fixed rules accept no remote feed, URL classifier or domain verdict, and the profile starts off.
Sign-in, payment, CAPTCHA, embedded-document, video, chat and support services may fail. Turn the profile or master protection off when compatibility is required.
The stricter rules have priority over ordinary per-site pause. While High-Risk Browsing is active, the pause control is unavailable so a lower-priority site exception cannot silently weaken the profile.
High-Risk Browsing does not detect Pegasus or other mercenary spyware, decide that a site is safe or malicious, scan downloads or messages, inspect browser or operating-system memory, or stop an unknown browser, extension, operating-system, kernel or baseband exploit. A zero-click attack may not involve browser navigation at all.
ZSEC Antivirus operates later and separately on selected changed files. That post-change companion does not turn these browser rules into exploit detection, pre-access file protection or a clean-device verdict.
A disposable Windows smoke test passed in current Brave and Edge builds: both request classes were blocked before reaching loopback test servers, and explicitly switching the profile off removed the rules and restored navigation.
Read the threat research, exact test boundary and high-risk operating guide.
Google’s Threat Analysis Group has documented commercial-surveillance campaigns involving injected HTTP redirects, watering holes and browser exploit chains. Citizen Lab has documented NSO Group zero-click chains that do not depend on browser navigation. These sources support layered, bounded controls; they do not test, certify or endorse ZSEC.
Google TAG: injected HTTP delivery · Google TAG: watering holes · Citizen Lab: BLASTPASS
Privacy contract
Community 0.4 has no analytics endpoint, advertising identifier, account requirement, spyware-verdict service or remote-control channel. Its privacy promise is specific and testable—not a vague “private mode” badge.
Browser security architecture
The Windows Community client uses Microsoft's serviced WebView2 Chromium runtime. A separately maintained ZSEC Chromium distribution would still have to preserve process separation, renderer sandbox and Site Isolation while sustaining rapid upstream security merges. The Community client does not claim to be that fork.
Current boundary · WebView2 Community client + auditable extension
Defined coverage and limitations
A transparent browser should show the user which controls are active, why a site broke and how to make a narrow site exception. It should not hide limitations behind a green shield.
Configured local ad and tracker rules, best-effort YouTube interface cleanup and optional High-Risk Browsing in compatible Chromium-based browsers.
Clear per-site controls, visible exceptions, permission explanations and no forced search provider or affiliate injection.
Every YouTube ad blocked, every malicious site prevented, anonymity, immunity from browser exploits or protection from all hackers.
Open-core boundary
Privacy claims are easier to test when the rules, extension source, threat model and packaging are public. Separately licensed services are labelled rather than hidden behind the word “open.”
Questions, answered plainly
ZSEC Browser Community 0.3.0 is an unsigned Windows WebView2 build with source and local acceptance evidence. It is not a separately maintained Chromium fork, a publisher-signed installer or a public native download. ZSEC Browser Shields 0.4 is the website evaluation extension package.
It applies local declarative blocking rules and best-effort interface cleanup. YouTube and other sites change frequently, so no honest blocker can promise uninterrupted coverage on every site.
Community 0.4 does not collect or upload browser history, page content, form data, cookies or search queries. It has no analytics, account or crash-upload endpoint.
No. The extension does not proxy traffic, install a local root certificate or break TLS. It works inside Chromium's extension boundary and does not weaken the browser sandbox or Site Isolation.
Download the versioned ZIP and checksum, calculate SHA-256 locally, compare the exact value, inspect the open source and load the unpacked package only in a dedicated Chromium profile.
Any browser distribution needs a deliberately small patch set, automated upstream monitoring, weekly and emergency security merges, signed update metadata, staged release rings and tested rollback. That operation has not shipped, so the project is not described as a maintained Chromium browser binary.
No. It applies only the two request restrictions disclosed on this page. It does not detect mercenary or commercial spyware, inspect messages or device memory, scan downloads, judge whether a site is safe, or stop an unknown browser, extension, operating-system, kernel or baseband exploit. A zero-click attack may not involve browser navigation at all. Keep supported software updated and seek qualified incident-response help after a credible targeting alert.
Privacy people can verify
ZSEC Browser Shields 0.4 is the installable open-source protection layer for compatible Chromium-family browsers, with versioned checksums, optional High-Risk Browsing and a complete local privacy contract.