yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2023-26081
Component Overview
Vulnerability Overview
Name
CVE-2023-26081
Source
NVD (
link
)
Debian (
link
)
Description
In Epiphany (aka GNOME Web) through 43.0, untrusted web content can trick users into exfiltrating passwords, because autofill occurs in sandboxed contexts.
CWEs
CWE-668
CWE-668
Published Date
Feb 20, 2023
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://github.com/google/security-research/security/advisories/GHSA-mhhf-w9xw-pp9x
Exploit
https://gitlab.gnome.org/GNOME/epiphany/-/merge_requests/1275
Patch
https://github.com/google/security-research/security/advisories/GHSA-mhhf-w9xw-pp9x
Exploit
https://gitlab.gnome.org/GNOME/epiphany/-/merge_requests/1275
Patch
Analysis
#
Affected Component
Analysis
epiphany
Exploitable
Vulnerability Ratings
#
7.5
CVSSv31
7.5
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
epiphany
yocto
master
50.4
Not Affected
epiphany
yocto
scarthgap
46.0
Not Affected