
PEACH
Un cadre d’isolation des locataires
CVE-2026-94291 is a local file exfiltration vulnerability in Epiphany (GNOME Web) caused by insecure iframe framing via the ephy-reader and view-source URI schemes. These schemes are not registered as display-isolated, allowing a remote attacker to embed them in iframes from web content and access local files when a user visits a malicious website. The CVE was published on September 18, 2026, and is classified as CWE-863 (Incorrect Authorization) with an estimated CVSS severity of Medium. Red Hat has confirmed this vulnerability does not affect any currently supported Red Hat products (Red Hat CVE, Red Hat Bugzilla).
The root cause is that Epiphany registers custom URI schemes (ephy-reader, view-source, ephy-webextension) without marking them as display-isolated via WebKit's webkit_security_manager_register_uri_scheme_as_display_isolated() API (CWE-863: Incorrect Authorization). Without this flag, WebKit's normal framing security controls do not prevent web content from embedding these schemes inside <iframe> elements from an HTTP context. Because ephy-reader and view-source can access local content, a malicious web page can leverage this to read and exfiltrate files from the user's local filesystem. The upstream fix is commit 25e1828903cb2419e18c437723b0f87fb5d31780, which registers the affected schemes as display-isolated (Red Hat Bugzilla).
Successful exploitation allows a remote attacker to exfiltrate local files from the victim's system without their knowledge, impacting confidentiality. The attack requires only that the user visit a malicious website using a vulnerable version of Epiphany (GNOME Web), with no additional authentication or privileges needed on the attacker's part. While the primary impact is unauthorized read access to local files, the Red Hat advisory notes that CWE-863 weaknesses can theoretically also enable modification of application data or privilege escalation in broader contexts (Red Hat CVE).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the available data. The CVE status remains "Reserved" and no EPSS score or CISA KEV catalog entry has been identified. Exploitation requires social engineering — the victim must visit an attacker-controlled website — but no authentication or special privileges are needed beyond that (Red Hat Bugzilla, Red Hat CVE).
<iframe> element with its src attribute set to a ephy-reader:// or view-source:// URI pointing to a target local file (e.g., view-source:///etc/passwd or ephy-reader:///home/user/.ssh/id_rsa).ephy-reader:// or view-source:// URIs referencing local file paths (e.g., /etc/passwd, ~/.ssh/) from within a web page context.The upstream fix is available as commit 25e1828903cb2419e18c437723b0f87fb5d31780 in the GNOME Epiphany repository, which registers ephy-reader and view-source URI schemes as display-isolated. Users should update Epiphany (GNOME Web) to a version that includes this fix. As a workaround, users can avoid using Epiphany as their primary browser until a patched package is available from their distribution. Red Hat has confirmed no currently supported Red Hat products are affected (Red Hat Bugzilla, Red Hat CVE).
Red Hat Product Security assessed this vulnerability and determined it does not affect any currently supported Red Hat products, noting the assessment may evolve with further analysis (Red Hat CVE). No significant broader media coverage, researcher commentary, or social media discussion has been identified for this CVE at this time.
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."