Debian Package Tracker
Register | Log in
Subscribe

epiphany-browser

Intuitive GNOME web browser

Choose email to subscribe with

general
  • source: epiphany-browser (main)
  • version: 50.4-2
  • maintainer: Debian GNOME Maintainers (archive) (DMD)
  • uploaders: Jeremy Bícha [DMD]
  • arch: all any
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 3.38.2-1+deb11u3
  • o-o-sec: 3.38.2-1+deb11u3
  • oldstable: 43.1-1
  • stable: 48.5-0+deb13u1
  • testing: 50.4-2
  • unstable: 50.4-2
versioned links
  • 3.38.2-1+deb11u3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 43.1-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 48.5-0+deb13u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 50.4-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • epiphany-browser (67 bugs: 0, 45, 22, 0)
  • epiphany-browser-data (5 bugs: 0, 5, 0, 0)
action needed
1 security issue in trixie high

There is 1 open security issue in trixie.

1 important issue:
  • CVE-2026-18487: A flaw was found in Epiphany. An issue in how the browser reads web addresses allows attackers to fake the domain name shown in the address bar. If a user clicks a specially crafted link containing a colon (for example, [https://trusted.com:80@attacker.com/](https://trusted.com:80@attacker.com/)), the address bar and security menus will display the safe website (trusted.com) but it will actually load the attacker website (attacker.com) on the screen. This allows attackers to create convincing phishing pages to trick users into trusting a malicious site.
Created: 2026-08-08 Last update: 2026-08-09 08:30
1 security issue in sid high

There is 1 open security issue in sid.

1 important issue:
  • CVE-2026-18487: A flaw was found in Epiphany. An issue in how the browser reads web addresses allows attackers to fake the domain name shown in the address bar. If a user clicks a specially crafted link containing a colon (for example, [https://trusted.com:80@attacker.com/](https://trusted.com:80@attacker.com/)), the address bar and security menus will display the safe website (trusted.com) but it will actually load the attacker website (attacker.com) on the screen. This allows attackers to create convincing phishing pages to trick users into trusting a malicious site.
Created: 2026-08-08 Last update: 2026-08-09 08:30
1 security issue in forky high

There is 1 open security issue in forky.

1 important issue:
  • CVE-2026-18487: A flaw was found in Epiphany. An issue in how the browser reads web addresses allows attackers to fake the domain name shown in the address bar. If a user clicks a specially crafted link containing a colon (for example, [https://trusted.com:80@attacker.com/](https://trusted.com:80@attacker.com/)), the address bar and security menus will display the safe website (trusted.com) but it will actually load the attacker website (attacker.com) on the screen. This allows attackers to create convincing phishing pages to trick users into trusting a malicious site.
Created: 2026-08-08 Last update: 2026-08-09 08:30
3 security issues in bullseye high

There are 3 open security issues in bullseye.

1 important issue:
  • CVE-2026-18487: A flaw was found in Epiphany. An issue in how the browser reads web addresses allows attackers to fake the domain name shown in the address bar. If a user clicks a specially crafted link containing a colon (for example, [https://trusted.com:80@attacker.com/](https://trusted.com:80@attacker.com/)), the address bar and security menus will display the safe website (trusted.com) but it will actually load the attacker website (attacker.com) on the screen. This allows attackers to create convincing phishing pages to trick users into trusting a malicious site.
2 issues postponed or untriaged:
  • CVE-2025-3839: (postponed; to be fixed through a stable update) A flaw was found in Epiphany, a tool that allows websites to open external URL handler applications with minimal user interaction. This design can be misused to exploit vulnerabilities within those handlers, making them appear remotely exploitable. The browser fails to properly warn or gate this action, resulting in potential code execution on the client device via trusted UI behavior.
  • CVE-2023-26081: (needs triaging) In Epiphany (aka GNOME Web) through 43.0, untrusted web content can trick users into exfiltrating passwords, because autofill occurs in sandboxed contexts.
Created: 2026-08-08 Last update: 2026-08-09 08:30
2 security issues in bookworm high

There are 2 open security issues in bookworm.

1 important issue:
  • CVE-2026-18487: A flaw was found in Epiphany. An issue in how the browser reads web addresses allows attackers to fake the domain name shown in the address bar. If a user clicks a specially crafted link containing a colon (for example, [https://trusted.com:80@attacker.com/](https://trusted.com:80@attacker.com/)), the address bar and security menus will display the safe website (trusted.com) but it will actually load the attacker website (attacker.com) on the screen. This allows attackers to create convincing phishing pages to trick users into trusting a malicious site.
1 issue postponed or untriaged:
  • CVE-2025-3839: (needs triaging) A flaw was found in Epiphany, a tool that allows websites to open external URL handler applications with minimal user interaction. This design can be misused to exploit vulnerabilities within those handlers, making them appear remotely exploitable. The browser fails to properly warn or gate this action, resulting in potential code execution on the client device via trusted UI behavior.
Created: 2026-08-08 Last update: 2026-08-09 08:30
2 new commits since last upload, is it time to release? normal
vcswatch reports that this package seems to have new commits in its VCS but has not yet updated debian/changelog. You should consider updating the Debian changelog and uploading this new version into the archive.

Here are the relevant commit logs:
commit d4910b12bf4fcc4a6e3c15d862d291d914ebf8e9
Author: Jeremy Bícha <jbicha@ubuntu.com>
Date:   Wed Jul 22 09:45:58 2026 +0200

    Update debian/upstream/metadata

commit dd126231fad51010f29bd1839687c5e242ecfde3
Author: Jeremy Bícha <jbicha@ubuntu.com>
Date:   Wed Jul 22 09:45:22 2026 +0200

    Use dh_auto_install -- --no-rebuild to avoid blhc failure


https://salsa.debian.org/api/v4/projects/gnome-team%2Fepiphany-browser API request failed: 401 Unauthorized at /srv/qa.debian.org/data/vcswatch/vcswatch line 410.
Created: 2026-07-22 Last update: 2026-08-09 00:30
debian/patches: 1 patch to forward upstream low

Among the 3 debian patches available in version 50.4-2 of the package, we noticed the following issues:

  • 1 patch where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2026-06-18 08:00
news
[rss feed]
  • [2026-06-23] epiphany-browser 50.4-2 MIGRATED to testing (Debian testing watch)
  • [2026-06-17] Accepted epiphany-browser 50.4-2 (source) into unstable (Jeremy Bícha)
  • [2026-04-29] epiphany-browser 50.4-1 MIGRATED to testing (Debian testing watch)
  • [2026-04-25] epiphany-browser 50.3-2 MIGRATED to testing (Debian testing watch)
  • [2026-04-24] Accepted epiphany-browser 50.4-1 (source) into unstable (Jeremy Bícha)
  • [2026-04-03] Accepted epiphany-browser 50.3-2 (source) into unstable (Jeremy Bícha)
  • [2026-04-01] Accepted epiphany-browser 50.3-1 (source) into unstable (Jeremy Bícha)
  • [2025-12-18] epiphany-browser 49.2-3 MIGRATED to testing (Debian testing watch)
  • [2025-12-11] Accepted epiphany-browser 49.2-3 (source) into unstable (Jeremy Bícha)
  • [2025-12-11] epiphany-browser 49.2-2 MIGRATED to testing (Debian testing watch)
  • [2025-12-06] Accepted epiphany-browser 49.2-2 (source) into unstable (Jeremy Bícha)
  • [2025-11-26] epiphany-browser 49.2-1 MIGRATED to testing (Debian testing watch)
  • [2025-11-20] Accepted epiphany-browser 49.2-1 (source) into unstable (Jeremy Bícha)
  • [2025-10-31] Accepted epiphany-browser 48.5-0+deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Jeremy Bícha)
  • [2025-10-16] epiphany-browser 49.1-1 MIGRATED to testing (Debian testing watch)
  • [2025-10-10] Accepted epiphany-browser 49.1-1 (source) into unstable (Jeremy Bícha)
  • [2025-09-18] epiphany-browser 49.0-1 MIGRATED to testing (Debian testing watch)
  • [2025-09-11] Accepted epiphany-browser 49.0-1 (source) into unstable (Jeremy Bícha)
  • [2025-09-08] epiphany-browser 48.5-3 MIGRATED to testing (Debian testing watch)
  • [2025-09-03] Accepted epiphany-browser 48.5-3 (source) into unstable (Simon McVittie)
  • [2025-08-18] epiphany-browser 48.5-2 MIGRATED to testing (Debian testing watch)
  • [2025-08-13] Accepted epiphany-browser 48.5-2 (source) into unstable (Jeremy Bícha) (signed by: Jeremy Bicha)
  • [2025-07-15] Accepted epiphany-browser 48.5-1 (source) into experimental (Simon McVittie)
  • [2025-05-13] epiphany-browser 48.3-2 MIGRATED to testing (Debian testing watch)
  • [2025-05-03] Accepted epiphany-browser 48.3-2 (source) into unstable (Matthias Klumpp)
  • [2025-04-27] epiphany-browser 48.2-1 MIGRATED to testing (Debian testing watch)
  • [2025-04-26] Accepted epiphany-browser 48.3-1 (source) into unstable (Jeremy Bícha) (signed by: Jeremy Bicha)
  • [2025-04-22] Accepted epiphany-browser 48.2-1 (source) into unstable (Jeremy Bícha) (signed by: Jeremy Bicha)
  • [2025-04-21] Accepted epiphany-browser 48.1-1 (source) into unstable (Jeremy Bícha) (signed by: Jeremy Bicha)
  • [2025-03-19] epiphany-browser 48.0-1 MIGRATED to testing (Debian testing watch)
  • 1
  • 2
bugs [bug history graph]
  • all: 75 77
  • RC: 0
  • I&N: 51 52
  • M&W: 24 25
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • screenshots
  • l10n (-, 87)
  • debian patches
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 50.4-2

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing