cbcvebase.
CVE-2026-18487
published 2026-08-06

CVE-2026-18487: A flaw was found in Epiphany. An issue in how the browser reads web addresses allows attackers to fake the domain name shown in the address bar. If a user…

PriorityP429medium5.4CVSS 3.1
AVNACLPRNUIRSUCLILAN
EPSS
0.31%
24.0th percentile
A flaw was found in Epiphany. An issue in how the browser reads web addresses allows attackers to fake the domain name shown in the address bar. If a user clicks a specially crafted link containing a colon (for example, [https://trusted.com:[email protected]/](https://trusted.com:[email protected]/)), the address bar and security menus will display the safe website (trusted.com) but it will actually load the attacker website (attacker.com) on the screen. This allows attackers to create convincing phishing pages to trick users into trusting a malicious site.

Affected

1 ranges
VendorProductVersion rangeFixed in
gnomeepiphany>= 49.2 < **
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.