CVE-2019-6251: High severity gnome epiphany vulnerability
embed/ephy-web-view.c in GNOME Web (aka Epiphany) through 3.31.4 allows address bar spoofing because a page load triggered by JavaScript leads to updating an address as if it were triggered by a safer visit type (e.g., VISITLINK, VISITTYPED, VISITBOOKMARK, or VISITHOMEPAGE).
Upstream issue: https://gitlab.gnome.org/GNOME/epiphany/issues/532
Other sources
WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar spoofing upon certain JavaScript redirections. An attacker could cause malicious web content to be displayed as if for a trusted URI. This is similar to the CVE-2018-8383 issue in Microsoft Edge.
— Launchpad
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-6251?
CVE-2019-6251 is a vulnerability in WebKitGTK and WPE WebKit that allows address bar spoofing upon certain JavaScript redirections.
How does CVE-2019-6251 impact users?
CVE-2019-6251 could allow an attacker to display malicious web content as if it is from a trusted source, potentially leading to phishing attacks or the theft of sensitive information.
What is the severity of CVE-2019-6251?
CVE-2019-6251 has a severity score of 8.1 out of 10, indicating a high level of risk.
Which versions of WebKitGTK and WPE WebKit are affected?
Versions prior to 2.24.1 of WebKitGTK and WPE WebKit are vulnerable to CVE-2019-6251.
How can I fix CVE-2019-6251?
To fix CVE-2019-6251, update WebKitGTK and WPE WebKit to version 2.24.1 or later.