CVE-2026-18487
Received Received - Intake

Address Bar Spoofing in GNOME Web (Epiphany)

Vulnerability report for CVE-2026-18487, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-06

Last updated on: 2026-08-06

Assigner: Fedora Project

Description

A flaw was found in Epiphany. An issue in how the browser reads web addresses allows attackers to fake the domain name shown in the address bar. If a user clicks a specially crafted link containing a colon (for example, [https://trusted.com:80@attacker.com/](https://trusted.com:80@attacker.com/)), the address bar and security menus will display the safe website (trusted.com) but it will actually load the attacker website (attacker.com) on the screen. This allows attackers to create convincing phishing pages to trick users into trusting a malicious site.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-06
Last Modified
2026-08-06
Generated
2026-08-07
AI Q&A
2026-08-07
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
epiphany epiphany *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-451 The user interface (UI) does not properly represent critical information to the user, allowing the information - or its source - to be obscured or spoofed. This is often a component in phishing attacks.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the Epiphany browser. It allows attackers to manipulate the address bar to display a fake trusted domain while loading a malicious site. For example, a link like https://trusted.com:80@attacker.com/ would show trusted.com in the address bar but load attacker.com.

Detection Guidance

This vulnerability involves Epiphany browser displaying fake domain names in the address bar. To detect it, check if users are accessing Epiphany and inspect network traffic for unusual URLs containing colons before the domain (e.g., trusted.com:80@attacker.com). No specific commands are provided in the context.

Impact Analysis

This vulnerability could trick you into visiting malicious websites that appear legitimate. It enables phishing attacks where attackers mimic trusted sites to steal login credentials or install malware. Users might unknowingly enter sensitive information on fake pages.

Mitigation Strategies

Update Epiphany to the latest version as soon as a patch is available. Avoid clicking suspicious links and educate users about verifying URLs before interacting. Disable JavaScript or use a different browser until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18487. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart