
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-3839 is an insecure external protocol invocation vulnerability in GNOME Epiphany (the GNOME web browser), classified under CWE-356 (Product UI does not Warn User of Unsafe Actions). The flaw allows websites to trigger external URL handler applications with insufficient user interaction or warning, potentially enabling code execution on the client device if the invoked handler application is itself vulnerable. Affected versions are Epiphany prior to 48.1 and 47.5. The vulnerability was reported on April 21, 2025, and formally published in the NVD on January 23, 2026. It carries a CVSS v3.1 base score of 8.0 (High), assigned by the Fedora Project (Red Hat Advisory, Red Hat Bugzilla).
The root cause is CWE-356: the browser fails to adequately warn or gate user interaction before invoking external URL handler applications registered on the system. When a malicious website crafts a link or redirect using a custom URI scheme (e.g., mailto:, tel:, or application-specific handlers), Epiphany opens the associated handler application without sufficient confirmation prompts. If the target handler application contains its own exploitable vulnerability, the attack surface effectively becomes remotely reachable through the browser. This design flaw makes locally vulnerable applications appear remotely exploitable, as the browser acts as a transparent bridge between a remote attacker-controlled web page and local system applications (Red Hat Bugzilla, Red Hat Advisory).
Successful exploitation can lead to code execution under the victim user's context by chaining this vulnerability with a flaw in an external URL handler application. The confidentiality and integrity impacts are rated High, as an attacker could potentially steal sensitive credentials, hijack sessions, or perform unauthorized actions on behalf of the victim. Availability is not directly impacted by this vulnerability itself. The scope is changed (S:C in CVSS), indicating that the impact extends beyond the browser to other components on the system (Red Hat Advisory, Red Hat Bugzilla).
There is no public proof-of-concept exploit or evidence of in-the-wild exploitation at this time. The vulnerability requires user interaction (the victim must visit a malicious web page) and high attack complexity, as exploitation depends on the presence of a vulnerable external URL handler on the target system. The EPSS score is approximately 0.014% (0.000140), indicating a very low probability of exploitation in the near term. CVE-2025-3839 does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection signatures are available via Nessus (plugin IDs 235676, 238460) and Qualys (IDs 287179, 287180) (Red Hat Advisory, Tenable Nessus).
mailto: handler or a custom URI scheme handler) that can be triggered via crafted URIs.<a href="customscheme://malicious-payload">Click here</a>) designed to invoke the vulnerable handler with a crafted payload.journald, syslog) showing invocation of external URI handler applications with unusual or encoded arguments; Epiphany or desktop environment logs recording custom URI scheme activations./tmp created by external handler applications at the time of exploitation; unexpected scripts or executables dropped by handler processes.Users should upgrade GNOME Epiphany to version 48.1 or 47.5, which address this vulnerability. Patches are available through Fedora (update advisory for Fedora 42) and openSUSE (advisory openSUSE-2025-15011-1). As a workaround, users can remove or restrict unnecessary external URL handler registrations on their systems to reduce the attack surface. Additionally, implementing Content Security Policy (CSP) headers on web servers and educating users about safe browsing practices can reduce risk. Administrators should prioritize patching systems where Epiphany is used as a default browser (Red Hat Bugzilla, Linux Security Fedora, Linux Security openSUSE).
The vulnerability received coverage in Linux security news outlets and was noted in CISA's weekly vulnerability bulletin for the week of January 19, 2026. A technical write-up was published by Infinit Security detailing the insecure external protocol invocation behavior. Social media activity was limited, with brief mentions on Mastodon (TheHackerWire) and Bluesky. Overall community reaction was moderate, reflecting the niche user base of GNOME Epiphany and the chained nature of the exploit (CISA Bulletin, Infinit Security).
Fix availability across major Linux distributions and their releases.
bookworm
epiphany-browser
sid
epiphany-browser: 48.1-1
trixie
epiphany-browser: 48.1-1
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."