CVE-2026-18487
published 2026-08-06CVE-2026-18487: A flaw was found in Epiphany. An issue in how the browser reads web addresses allows attackers to fake the domain name shown in the address bar. If a user…
PriorityP429medium5.4CVSS 3.1
AVNACLPRNUIRSUCLILAN
EPSS
0.31%
24.0th percentile
A flaw was found in Epiphany. An issue in how the browser reads web addresses allows attackers to fake the domain name shown in the address bar. If a user clicks a specially crafted link containing a colon (for example, [https://trusted.com:[email protected]/](https://trusted.com:[email protected]/)), the address bar and security menus will display the safe website (trusted.com) but it will actually load the attacker website (attacker.com) on the screen. This allows attackers to create convincing phishing pages to trick users into trusting a malicious site.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnome | epiphany | >= 49.2 < * | * |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
GNOME Epiphany clickjacking (Nessus ID 333350)
vuldb·2026-08-30·CVSS 5.4
CVE-2026-18487 [MEDIUM] GNOME Epiphany clickjacking (Nessus ID 333350)
A vulnerability categorized as problematic has been discovered in GNOME Epiphany. The affected element is an unknown function. Such manipulation leads to clickjacking.
This vulnerability is traded as CVE-2026-18487. The attack may be launched remotely. There is no exploit available.
GHSA
A flaw was found in Epiphany.
ghsa_unreviewed·2026-08-07
CVE-2026-18487 [MEDIUM] CWE-451 A flaw was found in Epiphany.
A flaw was found in Epiphany. An issue in how the browser reads web addresses allows attackers to fake the domain name shown in the address bar. If a user clicks a specially crafted link containing a colon (for example, [https://trusted.com:[email protected]/](https://trusted.com:[email protected]/)), the address bar and security menus will display the safe website (trusted.com) but it will actually load the attacker website (attacker.com) on the screen. This allows attackers to create convincing phishing pages to trick users into trusting a malicious site.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-18487 epiphany: address bar / host spoofing via userinfo in ephy_uri_get_decoded_host() [fedora-all]
bugzilla·2026-07-31
CVE-2026-18487 [MEDIUM] CVE-2026-18487 epiphany: address bar / host spoofing via userinfo in ephy_uri_get_decoded_host() [fedora-all]
CVE-2026-18487 epiphany: address bar / host spoofing via userinfo in ephy_uri_get_decoded_host() [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A flaw was found in Epiphany, affecting versions 49.2 and newer. An issue in how the browser reads web addresses allows attackers to fake the domain name shown in the address bar. If a user clicks a specially crafted link containing a colon (for example, [https://trusted.com:[email protected]/](https://trusted.com:[email protected]/)), the address bar and security menus will display the safe website (trusted.com) but it will actually load the attacker website (att
Bugzilla
CVE-2026-18487 epiphany: address bar / host spoofing via userinfo in ephy_uri_get_decoded_host()
bugzilla·2026-07-30
CVE-2026-18487 [MEDIUM] CVE-2026-18487 epiphany: address bar / host spoofing via userinfo in ephy_uri_get_decoded_host()
CVE-2026-18487 epiphany: address bar / host spoofing via userinfo in ephy_uri_get_decoded_host()
A flaw was found in Epiphany, affecting versions 49.2 and newer. An issue in how the browser reads web addresses allows attackers to fake the domain name shown in the address bar. If a user clicks a specially crafted link containing a colon (for example, [https://trusted.com:[email protected]/](https://trusted.com:[email protected]/)), the address bar and security menus will display the safe website (trusted.com) but it will actually load the attacker website (attacker.com) on the screen. This allows attackers to create convincing phishing pages to trick users into trusting a malicious site.
2026-08-06
Published