CVE-2026-94292
Description
A flaw was found in Epiphany (GNOME Web). The autofill visibility check only tests an element's on-screen size and fails to detect form fields hidden via CSS properties such as display:none, visibility:hidden, or opacity:0. A malicious web page can include hidden form fields that are silently populated with sensitive data, including credit card numbers, when the user triggers autofill.
Statement
Red Hat Product Security has determined that this vulnerability does not affect any currently supported Red Hat product. This assessment may evolve based on further analysis and discovery. For more information about this vulnerability and the products it affects, please see the linked references.
Mitigation
Disable the form autofill feature in Epiphany preferences, or ensure that sensitive personal and financial information is not stored in the autofill settings. Avoid using autofill on untrusted websites.
Understanding the Weakness (CWE)
Access Control
Technical Impact: Bypass Protection Mechanism
Acknowledgements
Upstream acknowledges Fernando Munoz as the original reporter.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.