In Epiphany (aka GNOME Web) through 43.0, untrusted web content can trick users into exfiltrating passwords, because autofill occurs in sandboxed contexts.
References
Configurations
History
18 Mar 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://gitlab.gnome.org/GNOME/epiphany/-/merge_requests/1275 - Patch, Vendor Advisory | |
References | () https://lists.debian.org/debian-lts-announce/2023/05/msg00015.html - | |
References | () https://github.com/google/security-research/security/advisories/GHSA-mhhf-w9xw-pp9x - Exploit, Third Party Advisory |
07 Nov 2023, 04:09
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
16 May 2023, 00:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
Information
Published : 2023-02-20 03:15
Updated : 2025-03-18 15:15
NVD link : CVE-2023-26081
Mitre link : CVE-2023-26081
JSON object : View
Products Affected
gnome
- epiphany
fedoraproject
- fedora
CWE
CWE-668
Exposure of Resource to Wrong Sphere