VDB

DEBIAN-CVE-2023-26081

DEBIAN-CVE-2023-26081 PUBLISHED CVSS 7.5 HIGH

In Epiphany (aka GNOME Web) through 43.0, untrusted web content can trick users into exfiltrating passwords, because autofill occurs in sandboxed contexts.

Risk Scores

CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected Products

VendorProductVersions
Debian:12epiphany-browser0, 0, 0
Debian:13epiphany-browser0, 0, 0
Debian:14epiphany-browser0, 0, 0
Debian:11epiphany-browser40~rc-1, 41.0-1, 41.0-2

Timeline

  • Feb 20, 2023 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›