CVE-2019-6251: Canonical Ubuntu Linux
High severity, CVSS 8.1. EPSS: 4.3% chance of exploitation in the next 30 days.
WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar spoofing upon certain JavaScript redirections. An attacker could cause malicious web content to be displayed as if for a trusted URI. This is similar to the CVE-2018-8383 issue in Microsoft Edge.
Affected products
- Canonical Ubuntu Linux: version 18.04 only; version 18.10 only
- Fedoraproject Fedora: version 28 only; version 29 only; version 30 only
- Gnome Epiphany: up to and including 3.31.4
- Opensuse Leap: version 15.0 only; version 42.3 only
- WebKitGTK WebKitGTK: before 2.24.1 (fixed in 2.24.1)
- Wpewebkit Wpe Webkit: before 2.24.1 (fixed in 2.24.1)
Published 2019-01-14. Last modified 2026-06-17.