CVE-2025-3839
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2025-3839 is an insecure external protocol invocation vulnerability in GNOME Epiphany (the GNOME web browser), classified under CWE-356 (Product UI does not Warn User of Unsafe Actions). The flaw allows websites to trigger external URL handler applications with insufficient user interaction or warning, potentially enabling code execution on the client device if the invoked handler application is itself vulnerable. Affected versions are Epiphany prior to 48.1 and 47.5. The vulnerability was reported on April 21, 2025, and formally published in the NVD on January 23, 2026. It carries a CVSS v3.1 base score of 8.0 (High), assigned by the Fedora Project (Red Hat Advisory, Red Hat Bugzilla).

Technical details

The root cause is CWE-356: the browser fails to adequately warn or gate user interaction before invoking external URL handler applications registered on the system. When a malicious website crafts a link or redirect using a custom URI scheme (e.g., mailto:, tel:, or application-specific handlers), Epiphany opens the associated handler application without sufficient confirmation prompts. If the target handler application contains its own exploitable vulnerability, the attack surface effectively becomes remotely reachable through the browser. This design flaw makes locally vulnerable applications appear remotely exploitable, as the browser acts as a transparent bridge between a remote attacker-controlled web page and local system applications (Red Hat Bugzilla, Red Hat Advisory).

Impact

Successful exploitation can lead to code execution under the victim user's context by chaining this vulnerability with a flaw in an external URL handler application. The confidentiality and integrity impacts are rated High, as an attacker could potentially steal sensitive credentials, hijack sessions, or perform unauthorized actions on behalf of the victim. Availability is not directly impacted by this vulnerability itself. The scope is changed (S:C in CVSS), indicating that the impact extends beyond the browser to other components on the system (Red Hat Advisory, Red Hat Bugzilla).

Exploitability

There is no public proof-of-concept exploit or evidence of in-the-wild exploitation at this time. The vulnerability requires user interaction (the victim must visit a malicious web page) and high attack complexity, as exploitation depends on the presence of a vulnerable external URL handler on the target system. The EPSS score is approximately 0.014% (0.000140), indicating a very low probability of exploitation in the near term. CVE-2025-3839 does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection signatures are available via Nessus (plugin IDs 235676, 238460) and Qualys (IDs 287179, 287180) (Red Hat Advisory, Tenable Nessus).

Exploitation steps

  1. Reconnaissance: Identify users running GNOME Epiphany versions prior to 48.1 or 47.5 on Linux systems, and determine what external URL handler applications (e.g., email clients, VoIP apps, custom protocol handlers) are registered on the target system.
  2. Identify vulnerable handler: Research known vulnerabilities in common external URL handler applications (e.g., a vulnerable mailto: handler or a custom URI scheme handler) that can be triggered via crafted URIs.
  3. Craft malicious web page: Create a web page containing a link or JavaScript redirect using a custom URI scheme (e.g., <a href="customscheme://malicious-payload">Click here</a>) designed to invoke the vulnerable handler with a crafted payload.
  4. Deliver to victim: Lure the target user to visit the malicious web page via phishing, malvertising, or a compromised site.
  5. Trigger handler invocation: When the victim interacts with the page (or in some cases, simply visits it), Epiphany opens the external handler application without adequate warning, passing the attacker-controlled URI/payload.
  6. Exploit handler vulnerability: The vulnerable handler application processes the malicious payload, resulting in code execution under the victim's user context (Red Hat Bugzilla, Red Hat Advisory).

Indicators of compromise

  • Network: Outbound connections from the user's system to unexpected external hosts shortly after visiting an unfamiliar website; DNS queries for suspicious domains initiated by non-browser processes.
  • Process: Unexpected spawning of external handler applications (e.g., email clients, VoIP apps, or custom URI scheme handlers) as child processes or shortly after browser activity; unusual child processes of handler applications (e.g., shell processes, scripting interpreters).
  • Logs: System logs (e.g., journald, syslog) showing invocation of external URI handler applications with unusual or encoded arguments; Epiphany or desktop environment logs recording custom URI scheme activations.
  • File System: New or modified files in the user's home directory or /tmp created by external handler applications at the time of exploitation; unexpected scripts or executables dropped by handler processes.

Mitigation and workarounds

Users should upgrade GNOME Epiphany to version 48.1 or 47.5, which address this vulnerability. Patches are available through Fedora (update advisory for Fedora 42) and openSUSE (advisory openSUSE-2025-15011-1). As a workaround, users can remove or restrict unnecessary external URL handler registrations on their systems to reduce the attack surface. Additionally, implementing Content Security Policy (CSP) headers on web servers and educating users about safe browsing practices can reduce risk. Administrators should prioritize patching systems where Epiphany is used as a default browser (Red Hat Bugzilla, Linux Security Fedora, Linux Security openSUSE).

Community reactions

The vulnerability received coverage in Linux security news outlets and was noted in CISA's weekly vulnerability bulletin for the week of January 19, 2026. A technical write-up was published by Infinit Security detailing the insecure external protocol invocation behavior. Social media activity was limited, with brief mentions on Mastodon (TheHackerWire) and Bluesky. Overall community reaction was moderate, reflecting the niche user base of GNOME Epiphany and the chained nature of the exploit (CISA Bulletin, Infinit Security).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

epiphany-browser

Affected

sid

epiphany-browser: 48.1-1

Fixed

trixie

epiphany-browser: 48.1-1

Fixed

Ubuntu

Unknown

bionic (esm-apps)

epiphany-browser

Unknown

devel

epiphany-browser

Not Affected

focal (esm-apps)

epiphany-browser

Unknown

jammy

epiphany-browser

Unknown

jammy (esm-apps)

epiphany-browser

Unknown

noble

epiphany-browser

Unknown

noble (esm-apps)

epiphany-browser

Unknown

resolute

epiphany-browser

Not Affected

SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-44950CRITICAL9.5
  • Rocky Linux logoRocky Linux
  • libXfont-debuginfo
NoYesSep 10, 2026
CVE-2026-59679CRITICAL9.2
  • Rocky Linux logoRocky Linux
  • libXfont2-doc
NoYesSep 10, 2026
CVE-2026-88924HIGH7
  • Linux Debian logoLinux Debian
  • gvfs-afp
NoNoSep 10, 2026
CVE-2026-87933MEDIUM5.5
  • Linux Debian logoLinux Debian
  • cjson
NoNoSep 10, 2026
CVE-2026-61915MEDIUM4.2
  • Linux Debian logoLinux Debian
  • cyrus-imapd-doc-extra
NoNoSep 09, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management