VDB

CVE-2025-3839

CVE-2025-3839 PUBLISHED CVSS 8 HIGH

A flaw was found in Epiphany, a tool that allows websites to open external URL handler applications with minimal user interaction. This design can be misused to exploit vulnerabilities within those handlers, making them appear remotely exploitable. The browser fails to properly warn or gate this action, resulting in potential code execution on the client device via trusted UI behavior.

EPSS 0.38% · 30.9th percentile

Risk Scores

CVSS 3.1
8
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N
EPSS Score
0.38%
30.9th percentile

Affected Products

VendorProductVersions
0, 48.0, 0

Timeline

  • Apr 22, 2025 CVE Published
  • May 10, 2025 PoC Published
  • Jan 23, 2026 EPSS Score
  • Jan 23, 2026 PoC Published
  • Jan 23, 2026 PoC Published
  • Jan 26, 2026 EPSS Score
  • Jan 26, 2026 CVE Updated
  • Jan 28, 2026 EPSS Score
  • Jan 31, 2026 EPSS Score
  • Feb 3, 2026 EPSS Score
  • Feb 5, 2026 EPSS Score
  • Feb 8, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›