CVE-2026-94291: 
Linux Debian Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-94291 is a local file exfiltration vulnerability in Epiphany (GNOME Web) caused by insecure iframe framing via the ephy-reader and view-source URI schemes. These schemes are not registered as display-isolated, allowing a remote attacker to embed them in iframes from web content and access local files when a user visits a malicious website. The CVE was published on September 18, 2026, and is classified as CWE-863 (Incorrect Authorization) with an estimated CVSS severity of Medium. Red Hat has confirmed this vulnerability does not affect any currently supported Red Hat products (Red Hat CVE, Red Hat Bugzilla).

Détails techniques

The root cause is that Epiphany registers custom URI schemes (ephy-reader, view-source, ephy-webextension) without marking them as display-isolated via WebKit's webkit_security_manager_register_uri_scheme_as_display_isolated() API (CWE-863: Incorrect Authorization). Without this flag, WebKit's normal framing security controls do not prevent web content from embedding these schemes inside <iframe> elements from an HTTP context. Because ephy-reader and view-source can access local content, a malicious web page can leverage this to read and exfiltrate files from the user's local filesystem. The upstream fix is commit 25e1828903cb2419e18c437723b0f87fb5d31780, which registers the affected schemes as display-isolated (Red Hat Bugzilla).

Impact

Successful exploitation allows a remote attacker to exfiltrate local files from the victim's system without their knowledge, impacting confidentiality. The attack requires only that the user visit a malicious website using a vulnerable version of Epiphany (GNOME Web), with no additional authentication or privileges needed on the attacker's part. While the primary impact is unauthorized read access to local files, the Red Hat advisory notes that CWE-863 weaknesses can theoretically also enable modification of application data or privilege escalation in broader contexts (Red Hat CVE).

Exploitabilité

No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the available data. The CVE status remains "Reserved" and no EPSS score or CISA KEV catalog entry has been identified. Exploitation requires social engineering — the victim must visit an attacker-controlled website — but no authentication or special privileges are needed beyond that (Red Hat Bugzilla, Red Hat CVE).

Étapes d’exploitation

  1. Reconnaissance: Identify users likely running Epiphany (GNOME Web) on Linux systems, particularly GNOME desktop environments.
  2. Craft malicious web page: Create an HTML page containing an <iframe> element with its src attribute set to a ephy-reader:// or view-source:// URI pointing to a target local file (e.g., view-source:///etc/passwd or ephy-reader:///home/user/.ssh/id_rsa).
  3. Host and deliver: Host the malicious page on an attacker-controlled server and lure the victim to visit it (e.g., via phishing, malvertising, or a compromised website).
  4. Exploit iframe framing: When the victim opens the page in Epiphany, the browser loads the local file content inside the iframe without enforcing display-isolation restrictions, bypassing WebKit's normal framing security controls.
  5. Exfiltrate data: Use JavaScript on the malicious page to read the iframe's content and transmit it to the attacker's server via an HTTP request (Red Hat Bugzilla).

Indicateurs de compromis

  • Network: Outbound HTTP/HTTPS requests from the user's machine to an unknown external server shortly after visiting a suspicious website, potentially carrying encoded local file content in request bodies or query parameters.
  • Logs: Browser or system logs showing access to ephy-reader:// or view-source:// URIs referencing local file paths (e.g., /etc/passwd, ~/.ssh/) from within a web page context.
  • Process: Epiphany (Web) process making unexpected file read operations on sensitive local paths while a web page is loaded.

Atténuation et solutions de contournement

The upstream fix is available as commit 25e1828903cb2419e18c437723b0f87fb5d31780 in the GNOME Epiphany repository, which registers ephy-reader and view-source URI schemes as display-isolated. Users should update Epiphany (GNOME Web) to a version that includes this fix. As a workaround, users can avoid using Epiphany as their primary browser until a patched package is available from their distribution. Red Hat has confirmed no currently supported Red Hat products are affected (Red Hat Bugzilla, Red Hat CVE).

Réactions de la communauté

Red Hat Product Security assessed this vulnerability and determined it does not affect any currently supported Red Hat products, noting the assessment may evolve with further analysis (Red Hat CVE). No significant broader media coverage, researcher commentary, or social media discussion has been identified for this CVE at this time.

Ressources additionnelles


Source: Ce rapport a été généré à l’aide de l’IA

Apparenté Linux Debian Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2019-25777HIGH8.1
  • Linux Debian logoLinux Debian
  • perl-YAML
NonOuiOct 05, 2026
CVE-2017-20285HIGH7.4
  • Linux Debian logoLinux Debian
  • libyaml-perl
NonOuiOct 05, 2026
CVE-2026-94291MEDIUM6.5
  • Linux Debian logoLinux Debian
  • epiphany-browser
NonNonOct 05, 2026
CVE-2026-97873MEDIUM5.3
  • Bouncy Castle logoBouncy Castle
  • bouncycastle
NonOuiOct 03, 2026
CVE-2026-19954NONEN/A
  • Linux Debian logoLinux Debian
  • libnet-whois-raw-perl
NonNonOct 05, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités