REDHAT-BUG-2361430: High severity Gnome Epiphany vulnerability
Epiphany prior to versions 48.1 and 47.5 allows websites to trigger external URL handlers with insufficient user interaction or warning. If the handler application is vulnerable, this opens the door to potential code execution under the user's context. This behavior misleads users and shifts the attack surface to local applications.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2361430?
The severity of REDHAT-BUG-2361430 is considered high due to the potential for code execution through exploited URL handlers.
How do I fix REDHAT-BUG-2361430?
To fix REDHAT-BUG-2361430, upgrade to Epiphany version 48.1 or later or 47.5 or later.
What versions of Epiphany are affected by REDHAT-BUG-2361430?
Epiphany versions prior to 48.1 and 47.5 are affected by REDHAT-BUG-2361430.
What is the risk associated with REDHAT-BUG-2361430?
The risk associated with REDHAT-BUG-2361430 involves potential code execution under the user's context through insufficiently controlled external URL handler activation.
Who is affected by REDHAT-BUG-2361430?
Users of Epiphany versions prior to 48.1 and 47.5 are affected by REDHAT-BUG-2361430.