Domain Spoofing Vulnerability in Epiphany Browser by GNOME
CVE-2026-18487

5.4MEDIUM

Key Information:

Vendor

Gnome

Status
Vendor
CVE Published:
6 August 2026

What is CVE-2026-18487?

A vulnerability in the Epiphany browser allows attackers to manipulate how web addresses are displayed, leading to potential domain spoofing. This flaw permits the browser to incorrectly show the address of a trusted site while actually loading a malicious site. By crafting a link with specific formatting, such as using a colon, attackers can create deceptive URLs that mislead users, thereby increasing the risk of successful phishing attempts. It is crucial for users and administrators to stay informed about this vulnerability and implement necessary updates to safeguard against such threats.

Affected Version(s)

Epiphany 49.2

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Fernando Munoz for reporting this issue.
.