Vulnerability Description
A flaw was found in Epiphany. An issue in how the browser reads web addresses allows attackers to fake the domain name shown in the address bar. If a user clicks a specially crafted link containing a colon (for example, [https://trusted.com:[email protected]/](https://trusted.com:[email protected]/)), the address bar and security menus will display the safe website (trusted.com) but it will actually load the attacker website (attacker.com) on the screen. This allows attackers to create convincing phishing pages to trick users into trusting a malicious site.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://access.redhat.com/security/cve/CVE-2026-18487
- https://bugzilla.redhat.com/show_bug.cgi?id=2509570
- https://gitlab.gnome.org/GNOME/epiphany/-/commit/0dde1d369458ac5c44b74b5ad3c433f
- https://gitlab.gnome.org/GNOME/epiphany/-/work_items/2897
FAQ
What is CVE-2026-18487?
CVE-2026-18487 is a vulnerability with a CVSS score of 5.4 (MEDIUM). A flaw was found in Epiphany. An issue in how the browser reads web addresses allows attackers to fake the domain name shown in the address bar. If a user clicks a specially crafted link containing a ...
How severe is CVE-2026-18487?
CVE-2026-18487 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-18487?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.