Windows Community 0.3.25 package · Browser Shields 0.5.2

A modern Windows browser with an inspectable protection engine.

ZSEC Browser Community 0.3.25 brings a separate local profile, tabs, bookmarks, bounded history suggestions, seven search providers, a review-first Sign-in Setup Assistant, a user-operated encrypted password vault, Balanced tracking prevention and 49,505 packaged network rules to Microsoft’s serviced WebView2 engine. Bounded YouTube controls and a Journalist high-risk preset stay transparent about their limits.

49,505 packaged network rules 7 search providers Local bookmarks and bounded history

Accepted Windows archive: 4,265,007 bytes · SHA-256 ecd59e8fb86560f0f2a4b5c645f956ef59e9140debcbbb25d6f3d3bd571ee548 · source cd0fff58072403dddaf3810aacbdb2288a01139d. The ZSEC executable is unsigned and uses Microsoft's maintained Evergreen WebView2 Chromium runtime. Its package gates pin Microsoft.Net.Compilers.Toolset 4.14.0, require deterministic compilation and reject machine-specific build paths. Keep WebView2 updates enabled and never bypass operating-system security warnings.

A verifiable browser shell with its own local profile.

The Community client has its own executable, rounded tabs, address bar, Desktop and Start-menu entries, separate profile, packaged network-isolated new-tab surface and runtime evidence. Microsoft maintains the Evergreen WebView2 Chromium engine; ZSEC maintains the shell, native request policy and bundled Browser Shields policy.

Windows application shell

Native ZSEC interface, managed tabs and downloads, bookmarks, bounded typed-history suggestions, seven selectable search providers, exact About information and no reuse of Chrome, Edge or Brave profiles.

Native request enforcement

The native filter receives all WebView2 resource-source kinds, blocks reviewed third-party tracker subresources and records an actual local script-request probe separately from policy self-tests.

Bounded YouTube protection

Exact-host document-start player-data sanitisation, reviewed endpoint blocking, known promotional-container hiding and visible skip-control activation complement Browser Shields. Playback is never sought, accelerated or muted, and permanent coverage is not promised.

Journalist preset

One explicit preset disables new app-history recording, requests app-history clearing on clean exit, and enables native strict cross-site and YouTube controls. It does not clear the WebView2 profile or detect spyware.

Restrictive defaults

Page-requested windows are blocked by default without creating or focusing another tab. A revocable exact-HTTPS origin permission still requires a WebView2-confirmed user request, an accepted HTTPS destination, the tab limit and burst guard; accepted requests open as independent tabs without a usable opener relationship. Site permissions default to deny; certificate errors are cancelled; ZSEC password saving and filling are opt-in; WebView2 password autosave, general autofill, host objects, developer tools and automatic download opening remain disabled. Popup blocking reduces exposure but cannot guarantee protection against every malicious site or browser-engine exploit.

Encrypted login workflow

The local vault stores website origins, usernames, passwords and notes under the Windows account. Optional save/update prompts require a native choice; optional fill matches only the exact HTTPS origin, never auto-submits and never syncs to ZSEC. It cannot protect an already compromised Windows session.

Review-first sign-in setup

Choose from a searchable built-in account catalog and exact HTTPS origins already in local ZSEC bookmarks/history. Every item starts unselected, paths and query strings are removed, and the exact origins are confirmed before opening. Source-browser cookies, sessions, tokens, passwords and profiles are never copied.

Runtime evidence contract

Acceptance separately records the extension declarative-rule probe, native policy self-test, actual native subresource probe, YouTube hook loading and observed interventions. No ad served is not treated as a failed intervention.

Accepted v0.3.25-browser Windows package

Download the 4,265,007-byte unsigned archive · checksum sidecar · release metadata · immutable source.

Archive SHA-256: ecd59e8fb86560f0f2a4b5c645f956ef59e9140debcbbb25d6f3d3bd571ee548. The 2,123-byte metadata JSON has SHA-256 67f230dcbad5c04c023285691bfe487f270162ce2f9ab49b596b46d558705857; the 122-byte checksum sidecar has SHA-256 488c50ea52a8e44c940541a0d8c21207b79e165ef8ba12f309d6dd8758c7f15a. Clean-build acceptance established same-toolchain exact bytes and no machine-specific manifest paths. It did not establish publisher signing, a maintained standalone Chromium fork or a release-specific installed-runtime result.

49,505 network rules. Per-site control. No history service.

The downloadable extension makes the protection layer useful now while keeping its permissions, blocking behaviour and complete source open to review.

Declarative local blocking

49,464 pinned EasyList rules and 39 focused privacy rules handle configured ad, analytics, fingerprinting and session-replay requests locally. Acceptable Ads is not included, and no remote browsing-history service is required.

Cleaner tracking links

Two top-level navigation rules remove common campaign identifiers such as utm_*, gclid and fbclid without a remote redirect service.

Best-effort YouTube assistance

A bounded content script can use visible skip controls and hide configured promoted slots. The site changes frequently, so perfect coverage is not promised.

One-click site pause

A local allow rule can recover a broken site without disabling protection everywhere. Paused domains remain visible in extension storage.

No interception or affiliate injection

ZSEC Browser Shields installs no root certificate, proxies no encrypted traffic, replaces no shopping links and forces no search provider.

Inspectable permissions and source

Every requested permission maps to a visible feature. Rules, source modules, tests, privacy contract and deterministic packager are public.

Blocking is not the same as total protection

Removing configured ads and trackers can reduce exposure and distraction. It cannot guarantee that every site, extension, download or account is safe. Browser and operating-system updates still matter.

Reduce selected browser exposure. Expect some sites to break.

Browser Shields High-Risk Browsing adds two fixed local Manifest V3 request rules. The Windows application's separate Journalist preset enables native strict cross-site controls, disables new local app-history recording, requests app-history clearing on clean exit and enables bounded YouTube protection. Neither mode is an ephemeral session or spyware detector.

Blocks plaintext pages

Top-level http:// navigation is blocked before the request is sent. HTTPS protects transport, but it does not prove that a site or its content is safe.

Restricts third-party active content

Third-party scripts, subframes, objects and WebSockets are blocked. First-party active content, images, media, stylesheets, fonts and fetch/XHR are not blanket-blocked.

Local and explicit

The preference stays in browser-local storage. The fixed rules accept no remote feed, URL classifier or domain verdict, and the profile starts off.

Designed to break more sites

Sign-in, payment, CAPTCHA, embedded-document, video, chat and support services may fail. Turn the profile or master protection off when compatibility is required.

The stricter rules have priority over ordinary per-site pause. While High-Risk Browsing is active, the pause control is unavailable so a lower-priority site exception cannot silently weaken the profile.

Exposure reduction is not spyware detection.

High-Risk Browsing does not detect Pegasus or other mercenary spyware, decide that a site is safe or malicious, scan downloads or messages, inspect browser or operating-system memory, or stop an unknown browser, extension, operating-system, kernel or baseband exploit. A zero-click attack may not involve browser navigation at all.

ZSEC Antivirus operates later and separately on selected changed files. That post-change companion does not turn these browser rules into exploit detection, pre-access file protection or a clean-device verdict.

Independent security context—not an endorsement

Google’s Threat Analysis Group has documented commercial-surveillance campaigns involving injected HTTP redirects, watering holes and browser exploit chains. Citizen Lab has documented NSO Group zero-click chains that do not depend on browser navigation. These sources support layered, bounded controls; they do not test, certify or endorse ZSEC.

Google TAG: injected HTTP delivery · Google TAG: watering holes · Citizen Lab: BLASTPASS

Browsing is not a telemetry product.

The Windows Community app stores bookmarks, bounded history and settings locally and adds no ZSEC history-sync or telemetry endpoint. Browser Shields 0.5.2 has no analytics endpoint, advertising identifier, account requirement, spyware-verdict service or remote-control channel. The selected search provider still receives the query and network metadata.

Community 0.5.2 does not collect

  • Browsing history or visited page content.
  • Form entries, cookies or search queries.
  • Private-browsing history or diagnostics.
  • Affiliate-attribution replacements.
  • Automatic page screenshots or memory contents.

Network expansion requires disclosure

  • Update checks disclose only documented release fields.
  • Diagnostics remain a separate opt-in.
  • URLs, query strings and user identifiers are scrubbed.
  • Sync must be independently encrypted before release.
  • Any policy change requires clear release notes.

Read the complete ZSEC Browser Shields privacy policy.

Microsoft services the engine; ZSEC controls the local shell and policy.

The Windows Community client uses Microsoft's serviced Evergreen WebView2 Chromium runtime and keeps its updates enabled. ZSEC maintains the browser shell, its separate local profile, restrictive settings, native request policy and bundled Browser Shields controls. It is not described as a separately maintained Chromium fork.

  • Never ship with the Chromium sandbox disabled.
  • Never install a root certificate to inspect traffic.
  • Keep Evergreen WebView2 servicing enabled.
  • Cancel certificate errors and default site permissions to deny.
  • Carry complete WebView2, EasyList and third-party licence notices.

What blocking can—and cannot—do.

A transparent browser should show the user which controls are active, why a site broke and how to make a narrow site exception. It should not hide limitations behind a green shield.

Community 0.3.25 package / 0.5.2

Native document-and-subresource filtering, bounded exact-host YouTube protection, local browser-data controls, 49,505 packaged network rules and optional strict browsing modes.

User control

Clear per-site controls, visible exceptions, permission explanations and no forced search provider or affiliate injection.

Not promised

Every YouTube ad blocked, every malicious site prevented, anonymity, immunity from browser exploits or protection from all hackers.

The browser core stays inspectable.

Privacy claims are easier to test when the rules, extension source, threat model and packaging are public. Separately licensed services are labelled rather than hidden behind the word “open.”

Public and auditable

  • ZSEC Browser privacy-extension package.
  • Local ad and tracker rules.
  • Permissions and privacy tests.
  • Threat models and same-toolchain exact-byte packaging tests.
  • Dependency, package-provenance and licence inventories.

Optional and separately operated

  • Production signing and offline root keys.
  • Managed reputation and enterprise administration.
  • Independently encrypted sync infrastructure.
  • Customer-support systems.
  • Licensed commercial threat intelligence.

ZSEC Browser FAQ

Is ZSEC Browser already a standalone browser?

ZSEC Browser Community 0.3.25 is an unsigned Windows WebView2 Community package with its own local profile and separate local encrypted password vault. It is not a separately maintained Chromium fork or a publisher-signed installer. Microsoft maintains and services the Evergreen WebView2 Chromium engine; ZSEC owns the shell, local policy and packaged Browser Shields controls.

Can ZSEC import my signed-in Facebook, X or Google session?

No. Copying live browser cookies or authentication tokens would move bearer credentials and create a high-value theft path. The Sign-in Setup Assistant instead shows exact HTTPS account origins from local ZSEC bookmarks/history and a reviewed built-in catalog, leaves every item unselected, asks for confirmation, and opens only the chosen origins. Sign in once inside ZSEC; the site's cookies can then persist in ZSEC's separate WebView2 profile.

Does ZSEC Browser block every YouTube ad?

When enabled on exact YouTube hosts, Community 0.3.25 combines packaged and native request blocking with bounded document-start player-data sanitisation, known promotional-container hiding and visible skip-control activation. It does not seek, accelerate or mute playback. Same-origin, server-inserted and changed advertising can still evade it, so uninterrupted coverage is not guaranteed.

Does ZSEC Browser collect browsing history?

The Windows application can save bounded history locally for address suggestions; recording can be disabled, cleared immediately or cleared on clean exit. It does not upload that history to ZSEC. Browser Shields 0.5.2 has no analytics, account or crash-upload endpoint.

Does ZSEC Browser install a root certificate or inspect encrypted traffic?

No. The extension does not proxy traffic, install a local root certificate or break TLS. It works inside Chromium's extension boundary and does not weaken the browser sandbox or Site Isolation.

How do I verify the ZSEC Browser Shields package?

Download the versioned ZIP and checksum, calculate SHA-256 locally, compare the exact value, inspect the open source and load the unpacked package only in a dedicated Chromium profile.

Why is ZSEC Browser not called a maintained Chromium fork?

Community 0.3.25 is deliberately a WebView2 shell rather than a separately maintained Chromium fork. Microsoft services the Evergreen WebView2 engine; ZSEC maintains its shell, local profile, native request policy and bundled Browser Shields controls.

Does High-Risk Browsing stop mercenary spyware or zero-click exploits?

No. It applies only the two request restrictions disclosed on this page. It does not detect mercenary or commercial spyware, inspect messages or device memory, scan downloads, judge whether a site is safe, or stop an unknown browser, extension, operating-system, kernel or baseband exploit. A zero-click attack may not involve browser navigation at all. Keep supported software updated and seek qualified incident-response help after a credible targeting alert.

Download the Windows browser or add the verifiable Shields package.

ZSEC Browser Community 0.3.25 is the accepted unsigned Windows WebView2 package. Browser Shields 0.5.2 remains the installable open-source protection layer for compatible Chromium-family browsers, with versioned checksums, optional High-Risk Browsing and a complete local privacy contract.