CVE-2026-18487: User Interface (UI) Misrepresentation of Critical Information in GNOME Epiphany
A flaw was found in Epiphany. An issue in how the browser reads web addresses allows attackers to fake the domain name shown in the address bar. If a user clicks a specially crafted link containing a colon (for example, [https://trusted.com:[email protected]/](https://trusted.com:[email protected]/)), the address bar and security menus will display the safe website (trusted.com) but it will actually load the attacker website (attacker.com) on the screen. This allows attackers to create convincing phishing pages to trick users into trusting a malicious site.
AI Analysis
Technical Summary
CVE-2026-18487 is a user interface misrepresentation vulnerability (CWE-451) in the Epiphany browser. The flaw arises from improper parsing of URLs containing a colon in the userinfo section, such as 'https://trusted.com:[email protected]/'. This causes the browser's address bar and security indicators to display the safe domain (trusted.com) while actually loading content from the attacker-controlled domain (attacker.com). This discrepancy can be exploited to create convincing phishing pages that deceive users into trusting malicious sites. The vulnerability has a CVSS 3.1 base score of 5.4 (medium severity) with network attack vector, low attack complexity, no privileges required, user interaction required, and limited confidentiality and integrity impact. No known exploits are reported in the wild. Red Hat's advisory states that no currently supported Red Hat products are affected.
Potential Impact
The vulnerability allows attackers to misrepresent the domain shown in the browser's address bar, potentially tricking users into trusting malicious websites. This can facilitate phishing attacks by hiding the true destination URL. The impact is limited to confidentiality and integrity with no reported impact on availability. There are no known active exploits targeting this vulnerability.
Mitigation Recommendations
Red Hat has confirmed that this vulnerability does not affect any currently supported Red Hat products, so no action is required for Red Hat users. For users of Epiphany browser outside of Red Hat products, check with the browser vendor for patches or updates addressing this issue. Patch status is not yet confirmed—consult the vendor advisory for current remediation guidance.
CVE-2026-18487: User Interface (UI) Misrepresentation of Critical Information in GNOME Epiphany
Description
A flaw was found in Epiphany. An issue in how the browser reads web addresses allows attackers to fake the domain name shown in the address bar. If a user clicks a specially crafted link containing a colon (for example, [https://trusted.com:[email protected]/](https://trusted.com:[email protected]/)), the address bar and security menus will display the safe website (trusted.com) but it will actually load the attacker website (attacker.com) on the screen. This allows attackers to create convincing phishing pages to trick users into trusting a malicious site.
CVSS v3.1
Score 5.4medium
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-18487 is a user interface misrepresentation vulnerability (CWE-451) in the Epiphany browser. The flaw arises from improper parsing of URLs containing a colon in the userinfo section, such as 'https://trusted.com:[email protected]/'. This causes the browser's address bar and security indicators to display the safe domain (trusted.com) while actually loading content from the attacker-controlled domain (attacker.com). This discrepancy can be exploited to create convincing phishing pages that deceive users into trusting malicious sites. The vulnerability has a CVSS 3.1 base score of 5.4 (medium severity) with network attack vector, low attack complexity, no privileges required, user interaction required, and limited confidentiality and integrity impact. No known exploits are reported in the wild. Red Hat's advisory states that no currently supported Red Hat products are affected.
Potential Impact
The vulnerability allows attackers to misrepresent the domain shown in the browser's address bar, potentially tricking users into trusting malicious websites. This can facilitate phishing attacks by hiding the true destination URL. The impact is limited to confidentiality and integrity with no reported impact on availability. There are no known active exploits targeting this vulnerability.
Mitigation Recommendations
Red Hat has confirmed that this vulnerability does not affect any currently supported Red Hat products, so no action is required for Red Hat users. For users of Epiphany browser outside of Red Hat products, check with the browser vendor for patches or updates addressing this issue. Patch status is not yet confirmed—consult the vendor advisory for current remediation guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-5w7g-jqwx-788x
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-18487"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a7573a5bf8831d539d9293b
Added to database: 08/07/2026, 05:56:53 UTC
Last enriched: 08/07/2026, 08:16:20 UTC
Last updated: 09/21/2026, 22:01:32 UTC
Views: 92
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.