Bug 2509570 (CVE-2026-18487) - CVE-2026-18487 epiphany: address bar / host spoofing via userinfo in ephy_uri_get_decoded_host()
Summary: CVE-2026-18487 epiphany: address bar / host spoofing via userinfo in ephy_uri...
Keywords:
Status: NEW
Alias: CVE-2026-18487
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2509773
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-30 19:32 UTC by OSIDB Bzimport
Modified: 2026-08-05 13:15 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-30 19:32:32 UTC
A flaw was found in Epiphany, affecting versions 49.2 and newer. An issue in how the browser reads web addresses allows attackers to fake the domain name shown in the address bar. If a user clicks a specially crafted link containing a colon (for example, [https://trusted.com:80@attacker.com/](https://trusted.com:80@attacker.com/)), the address bar and security menus will display the safe website (trusted.com) but it will actually load the attacker website (attacker.com) on the screen. This allows attackers to create convincing phishing pages to trick users into trusting a malicious site.


Note You need to log in before you can comment on or make changes to this bug.