Bug 2537348 (CVE-2026-94292) - CVE-2026-94292 epiphany: Insecure autofill visibility check allows silent exfiltration of sensitive data via CSS-hidden form fields
Summary: CVE-2026-94292 epiphany: Insecure autofill visibility check allows silent exf...
Keywords:
Status: NEW
Alias: CVE-2026-94292
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2537349
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-21 09:52 UTC by OSIDB Bzimport
Modified: 2026-09-21 09:56 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-21 09:52:20 UTC
A flaw was found in Epiphany's form autofill feature. The EphyAutofill.isVisible() function only checks an element's on-screen size and does not detect fields hidden via CSS properties such as display:none, visibility:hidden, or opacity:0. A malicious web page can include hidden form fields that are silently populated with sensitive data (personal information, credit card numbers) when the user triggers autofill. The hidden field values can then be exfiltrated via JavaScript.

This is particularly impactful in Epiphany because credit card information is autofilled directly without requiring CVV confirmation, unlike other browsers.

Upstream issue: https://gitlab.gnome.org/GNOME/epiphany/-/work_items/2951

Comment 1 Mauro Matteo Cascella 2026-09-21 09:53:39 UTC
Upstream issue:
https://gitlab.gnome.org/GNOME/epiphany/-/work_items/2951


Note You need to log in before you can comment on or make changes to this bug.