https://github.com/scowser/scowser
scowser is the secure browser
https://github.com/scowser/scowser
browser scowser secure-browser secure-browsing
Last synced: 17 days ago
JSON representation
scowser is the secure browser
- Host: GitHub
- URL: https://github.com/scowser/scowser
- Owner: scowser
- License: apache-2.0
- Created: 2026-03-27T17:51:05.000Z (3 months ago)
- Default Branch: main
- Last Pushed: 2026-04-05T22:48:26.000Z (3 months ago)
- Last Synced: 2026-04-06T00:32:52.677Z (3 months ago)
- Topics: browser, scowser, secure-browser, secure-browsing
- Language: C++
- Homepage: https://scowser.com
- Size: 492 KB
- Stars: 1
- Watchers: 0
- Forks: 0
- Open Issues: 0
-
Metadata Files:
- Readme: README.md
- Contributing: CONTRIBUTING.md
- License: LICENSE
- Code of conduct: CODE_OF_CONDUCT.md
- Codeowners: .github/CODEOWNERS
- Security: SECURITY.md
Awesome Lists containing this project
README
# scowser
A security-focused web browser built in C++ with Qt6 WebEngine.
## Features
- **Sandboxed Tabs** — Each tab runs in an isolated process with OS-level sandboxing
- **Ad & Tracker Blocking** — Built-in EasyList/EasyPrivacy filtering, no extensions needed
- **DNS-over-HTTPS** — Encrypted DNS via Cloudflare or Quad9, preventing ISP snooping
- **Zero Telemetry** — No analytics, no crash reports, no data collection whatsoever
- **Strict TLS** — Certificate pinning, TLS 1.2+ only, certificate transparency checks
- **Security Indicator** — Lock icon in the address bar shows connection security at a glance
- **CSP Enforcement** — Content Security Policy headers injected and enforced
- **Ephemeral by Default** — All browsing data wiped on exit; no persistent cookies, cache, or history. Right-click any tab to save its session and persist cookies, cache, and local storage across restarts
- **Dark Theme** — Custom dark UI with SVG icons, styled tabs, toolbar, and address bar
- **Configurable Settings** — DNS provider, search engine, ad blocking, JavaScript, and privacy options via a built-in settings dialog
- **Download Manager** — Built-in download handling with progress tracking, configurable download directory, and toolbar indicator
- **Favorites** — Full-featured bookmarks system with groups, pinning, drag-and-drop reordering, search, and persistent storage; star button in toolbar, Ctrl+D to toggle, Ctrl+B for panel
- **Live Log Viewer** — Built-in log panel with syntax-highlighted output, dockable as a vertical or horizontal pane via the View menu
- **DevTools** — Full Chromium developer tools (elements, console, network, sources) in a dockable panel; F12 or Ctrl+Shift+I to toggle, follows the active tab
## Install
**macOS (Homebrew Cask):**
```bash
brew tap scowser/scowser
brew install --cask scowser
```
**Linux (Homebrew Formula):**
```bash
brew tap scowser/scowser
brew install scowser
```
## Building from Source
### Prerequisites
- C++20 compiler (Clang 14+ or GCC 12+)
- CMake 3.22+
- Qt6 6.5+ with WebEngine module
**macOS:**
```bash
brew install qt@6 cmake
```
**Linux (Debian/Ubuntu):**
```bash
sudo apt install qt6-webengine-dev qt6-base-dev libqt6svg6-dev cmake g++
```
**Linux (Fedora):**
```bash
sudo dnf install qt6-qtwebengine-devel qt6-qtbase-devel qt6-qtsvg-devel cmake gcc-c++
```
### Compile & Run
```bash
cmake -B build -DCMAKE_BUILD_TYPE=Release
cmake --build build --parallel
./build/scowser
```
### Run Tests
```bash
cmake -B build -DBUILD_TESTING=ON
cmake --build build --parallel
ctest --test-dir build --output-on-failure
```
## Architecture
scowser embeds Chromium via Qt6 WebEngine and layers security controls on top:
```
┌─────────────────────────────────┐
│ scowser UI │
│ (MainWindow, Tabs, AddressBar) │
├─────────────────────────────────┤
│ Security Layer │
│ AdBlocker · DoH · CertPinner │
│ CSP Enforcer · SessionManager │
├─────────────────────────────────┤
│ Request Interceptor │
│ (filters all network traffic) │
├─────────────────────────────────┤
│ Qt6 WebEngine (Chromium) │
│ (rendering, JS, sandboxing) │
└─────────────────────────────────┘
```
## Security Model
| Threat | Mitigation |
|-------------------------|-----------------------------------------------|
| Ad/tracker surveillance | Request-level blocking via filter lists |
| DNS snooping | DNS-over-HTTPS with trusted resolvers |
| Data exfiltration | Zero telemetry, ephemeral sessions |
| MITM attacks | Certificate pinning, strict TLS, CT checks |
| XSS / injection | CSP enforcement on all pages |
| Tab compromise | Process isolation + OS-level sandboxing |
## License
See [LICENSE](LICENSE) for details.