Domain Spoofing Vulnerability in Epiphany Browser by GNOME
CVE-2026-18487
5.4MEDIUM
What is CVE-2026-18487?
A vulnerability in the Epiphany browser allows attackers to manipulate how web addresses are displayed, leading to potential domain spoofing. This flaw permits the browser to incorrectly show the address of a trusted site while actually loading a malicious site. By crafting a link with specific formatting, such as using a colon, attackers can create deceptive URLs that mislead users, thereby increasing the risk of successful phishing attempts. It is crucial for users and administrators to stay informed about this vulnerability and implement necessary updates to safeguard against such threats.
Affected Version(s)
Epiphany 49.2
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Fernando Munoz for reporting this issue.