CVE-2023-26081: High severity gnome epiphany vulnerability
In Epiphany (aka GNOME Web) through 43.0, untrusted web content can trick users into exfiltrating passwords, because autofill occurs in sandboxed contexts.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-26081?
CVE-2023-26081 is a vulnerability in Epiphany (aka GNOME Web) through version 43.0 that allows untrusted web content to trick users into exfiltrating passwords.
What software versions are affected by CVE-2023-26081?
Epiphany versions up to and including 43.0 are affected by CVE-2023-26081.
How can untrusted web content trick users into exfiltrating passwords in CVE-2023-26081?
Untrusted web content can trick users into exfiltrating passwords in CVE-2023-26081 by taking advantage of autofill occurring in sandboxed contexts.
What is the severity of CVE-2023-26081?
CVE-2023-26081 has a severity rating of 7.5, which is classified as high.
Where can I find more information about CVE-2023-26081?
More information about CVE-2023-26081 can be found at the following references: [link1](https://github.com/google/security-research/security/advisories/GHSA-mhhf-w9xw-pp9x), [link2](https://gitlab.gnome.org/GNOME/epiphany/-/merge_requests/1275), [link3](https://lists.debian.org/debian-lts-announce/2023/05/msg00015.html)