Fedora Account System
Red Hat Associate
Red Hat Customer
Epiphany (GNOME Web) registers custom URI schemes (ephy-reader, view-source, ephy-webextension) without marking them as display-isolated. This allows a malicious web page to embed these schemes in iframes from an HTTP context, bypassing WebKit's normal framing security controls. Because the ephy-reader and view-source schemes can access local content, an attacker-controlled web page can use this to exfiltrate local files from the user's system. Exploitation requires the user to visit a malicious website. The fix (commit 25e1828903cb2419e18c437723b0f87fb5d31780) registers these schemes as display-isolated via webkit_security_manager_register_uri_scheme_as_display_isolated(), preventing web content from framing them. Upstream issue: https://gitlab.gnome.org/GNOME/epiphany/-/work_items/2952 Upstream fix: https://gitlab.gnome.org/GNOME/epiphany/-/commit/25e1828903cb2419e18c437723b0f87fb5d31780
Upstream issue: https://gitlab.gnome.org/GNOME/epiphany/-/work_items/2952 Upstream fix: https://gitlab.gnome.org/GNOME/epiphany/-/commit/25e1828903cb2419e18c437723b0f87fb5d31780