In Epiphany (aka GNOME Web) through 43.0, untrusted web content can trick users into exfiltrating passwords, because autofill occurs in sandboxed contexts.
References
Configurations
History
21 Nov 2024, 07:50
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/google/security-research/security/advisories/GHSA-mhhf-w9xw-pp9x - Exploit, Third Party Advisory | |
References | () https://gitlab.gnome.org/GNOME/epiphany/-/merge_requests/1275 - Patch, Vendor Advisory | |
References | () https://lists.debian.org/debian-lts-announce/2023/05/msg00015.html - | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IFWUNG6E4ZT43EYNHKYXS7QVSO2VW2H2/ - | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SADQCSQKTJKTTIJMEPY7GII6IVQSKEKV/ - |
07 Nov 2023, 04:09
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
16 May 2023, 00:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
Information
Published : 2023-02-20 03:15
Updated : 2025-03-18 15:15
NVD link : CVE-2023-26081
Mitre link : CVE-2023-26081
CVE.ORG link : CVE-2023-26081
JSON object : View
Products Affected
gnome
- epiphany
fedoraproject
- fedora
CWE
CWE-668
Exposure of Resource to Wrong Sphere