AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-18487

MEDIUM · CVSS 5.4 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

A vulnerability in the Epiphany browser allows attackers to manipulate the displayed domain name in the address bar, enabling them to create convincing phishing links that mislead users into believing they are visiting a legitimate site. This flaw can lead to unauthorized access to sensitive information, making it critical for users and organizations relying on Epiphany to prioritize updates and implement security measures against phishing attacks. Users should exercise caution when clicking on links and verify URLs to mitigate potential risks.

CVE
CVE-2026-18487
Severity
MEDIUM
CVSS
5.4
EPSS
0.32%

Original NVD Description

A flaw was found in Epiphany. An issue in how the browser reads web addresses allows attackers to fake the domain name shown in the address bar. If a user clicks a specially crafted link containing a colon (for example, [https://trusted.com:80@attacker.com/](https://trusted.com:80@attacker.com/)), the address bar and security menus will display the safe website (trusted.com) but it will actually load the attacker website (attacker.com) on the screen. This allows attackers to create convincing phishing pages to trick users into trusting a malicious site.