#1143966 epiphany-browser: CVE-2026-18487

Package:
src:epiphany-browser
Source:
src:epiphany-browser
Submitter:
Salvatore Bonaccorso
Date:
2026-08-30 16:07:02 UTC
Severity:
normal
Tags:
#1143966#5
Date:
2026-08-09 05:13:43 UTC
From:
To:
Hi,

The following vulnerability was published for epiphany-browser.

CVE-2026-18487[0]:
| A flaw was found in Epiphany. An issue in how the browser reads web
| addresses allows attackers to fake the domain name shown in the
| address bar. If a user clicks a specially crafted link containing a
| colon (for example, [https://trusted.com:80@attacker.com/](https://t
| rusted.com:80@attacker.com/)), the address bar and security menus
| will display the safe website (trusted.com) but it will actually
| load the attacker website (attacker.com) on the screen. This allows
| attackers to create convincing phishing pages to trick users into
| trusting a malicious site.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-18487
https://www.cve.org/CVERecord?id=CVE-2026-18487
[1] https://gitlab.gnome.org/GNOME/epiphany/-/work_items/2897
[2] https://gitlab.gnome.org/GNOME/epiphany/-/commit/13dd600719d7aac532ed6c84ea0d12dd372d4ac4

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1143966#10
Date:
2026-08-30 16:05:30 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
epiphany-browser, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1143966@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Jeremy Bícha <jbicha@ubuntu.com> (supplier of updated epiphany-browser package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sun, 30 Aug 2026 17:48:24 +0200
Source: epiphany-browser
Built-For-Profiles: derivative.ubuntu noudeb
Architecture: source
Version: 51~rc-1
Distribution: unstable
Urgency: high
Maintainer: Debian GNOME Maintainers <pkg-gnome-maintainers@lists.alioth.debian.org>
Changed-By: Jeremy Bícha <jbicha@ubuntu.com>
Closes: 1143966 1145177
Changes:
 epiphany-browser (51~rc-1) unstable; urgency=high
 .
   * New upstream release
     - SECURITY UPDATE: Fix address bar spoofing
       - CVE-2026-18487 (Closes: #1143966)
     - SECURITY UPDATE: Fix form autofill vulnerability
       - CVE-2026-77682 (Closes: #1145177)
   * Add Build-Depends: libpwquality-dev
   * Update minimum glib
Checksums-Sha1:
 5f199529edec374432fc62cfa11a2d3b23604d0e 2703 epiphany-browser_51~rc-1.dsc
 3eb00497221f3086db91a46032682c8d0732e42b 4598336 epiphany-browser_51~rc.orig.tar.xz
 b0abc11efe4588a2feac1bfac1c64f31c7e66ce9 44624 epiphany-browser_51~rc-1.debian.tar.xz
 7a28db86fe97cc642142362a73571f13b230f4cc 11478 epiphany-browser_51~rc-1_source.buildinfo
Checksums-Sha256:
 070c71c4e5ffd7aaa66c712083ad003ab3ab0d3e0befc57b6e7dfeb115e53e8c 2703 epiphany-browser_51~rc-1.dsc
 14d585c0fa509a089f52a95621992cc2f9fec4fbd60d4a6c794b7f94e73bbd0c 4598336 epiphany-browser_51~rc.orig.tar.xz
 d37acc557eca1f94d02e1f907123558587915c15c03241a3984af87cc5f76821 44624 epiphany-browser_51~rc-1.debian.tar.xz
 b98be3c5978aac69f16621e64fa28ae22b852bcd34192a3f94268c64075985a3 11478 epiphany-browser_51~rc-1_source.buildinfo
Files:
 1b07c36bff6291b1c1ae498a837872eb 2703 gnome optional epiphany-browser_51~rc-1.dsc
 f0cb1bef39154d224c4456a6799c5a98 4598336 gnome optional epiphany-browser_51~rc.orig.tar.xz
 606b6734b4d131d3ab079681200889b2 44624 gnome optional epiphany-browser_51~rc-1.debian.tar.xz
 020a7d83f2e1d0d730a8de5a2d78ebbd 11478 gnome optional epiphany-browser_51~rc-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEETQvhLw5HdtiqzpaW5mx3Wuv+bH0FAmqUUg0ACgkQ5mx3Wuv+
bH2knQ//XDHJ/38GPsZdd3r/3Ho/tiCH69SXiFOyvNbUVVI2KOmc5ef8rQscfhwU
CB/NKchU0vgV+3XJzUBtuDjqpaMYJ3JqXC0Mec44geO++P6CLdS2R1dhDVa1uEVV
TpEChqh5F60w/zMH7w7Y1+qes1bp1CAhgPXkj3aeQ82WjmAx/a9Q9uq1QeB5SfsU
oBCDL/OffO/mn9olipJwrUrxqfxEwx7lKZ84j3daDYhwa78vgEms8uf5TK+POiNr
DJe7vraOGu1TelLHNflxfExTEqxhudxNKeM0yhGVRqgsX4rn9pdbpCyHSO0zRHyO
ue79RpkoYo07NfQv5CotEI/HfiG9DAzrAw/PMz/hbytTH12/TX1acpd7xV1zYdok
5GhAbJ1XjJtbrguNhYz/3FNvGITHnbr8VfXSGYwq4hYPGWpEJ1p3jPqcwLpySJsa
23fXhOr+q/K20U/mo7TQBRldPvGbnkADplIZ6jxCRS1mHlGlsXSNzP7I6Gc107pR
Hl92YfG22JhFTzbnD1h2dXsGtCLrHe0gSPD8eHYuMNhJy+tDGu8jq7rekrBegreb
waYcKzocWbnSuqR4ZKJ21878vxOLjE+aHh2MLtiLVI4OaKtyXveVeGC9m8tIALae
ptt8FcLtYStc4fa2FNBGX41DOKl/P0S/WEgwVJEXH83+Dn0f5AM=
=d5YE
-----END PGP SIGNATURE-----