Remote Code Execution Vulnerability in Epiphany by Red Hat
CVE-2025-3839

8HIGH

Key Information:

Status
Vendor
CVE Published:
23 January 2026

What is CVE-2025-3839?

A design flaw in Epiphany, an application by Red Hat that enables web pages to interact with external URL handlers, can be exploited to launch code execution attacks on client devices. This vulnerability arises from the software's inability to adequately manage user interaction and warn users about potentially harmful actions. Through this exploit, malicious actors can manipulate trusted user interface behaviors, causing significant security risks for users, as these actions can be initiated with minimal user consent.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Michael Catanzaro for reporting this issue.
.