A flaw was found in Epiphany. An issue in how the browser reads web addresses allows attackers to fake the domain name shown in the address bar. If a user clicks a specially crafted link containing a colon (for example, [https://trusted.com:[email protected]/](https://trusted.com:[email protected]/)), the address bar and security menus will display the safe website (trusted.com) but it will actually load the attacker website (attacker.com) on the screen. This allows attackers to create convincing phishing pages to trick users into trusting a malicious site.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 07 Aug 2026 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gnome
Gnome epiphany |
|
| Vendors & Products |
Gnome
Gnome epiphany |
Thu, 06 Aug 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Epiphany. An issue in how the browser reads web addresses allows attackers to fake the domain name shown in the address bar. If a user clicks a specially crafted link containing a colon (for example, [https://trusted.com:[email protected]/](https://trusted.com:[email protected]/)), the address bar and security menus will display the safe website (trusted.com) but it will actually load the attacker website (attacker.com) on the screen. This allows attackers to create convincing phishing pages to trick users into trusting a malicious site. | |
| Title | Epiphany: address bar / host spoofing via userinfo in ephy_uri_get_decoded_host() | |
| Weaknesses | CWE-451 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: fedora
Published:
Updated: 2026-08-06T16:32:39.361Z
Reserved: 2026-07-31T13:30:18.349Z
Link: CVE-2026-18487
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-07T00:15:04Z
Weaknesses