CVE-2023-26081: Fedoraproject Fedora
High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.
In Epiphany (aka GNOME Web) through 43.0, untrusted web content can trick users into exfiltrating passwords, because autofill occurs in sandboxed contexts.
Affected products
- Fedoraproject Fedora: version 37 only
- Gnome Epiphany: before 43.1 (fixed in 43.1)
Published 2023-02-20. Last modified 2026-06-17.