CVE-2026-94292

Description

A flaw was found in Epiphany (GNOME Web). The autofill visibility check only tests an element's on-screen size and fails to detect form fields hidden via CSS properties such as display:none, visibility:hidden, or opacity:0. A malicious web page can include hidden form fields that are silently populated with sensitive data, including credit card numbers, when the user triggers autofill.

Statement

Red Hat Product Security has determined that this vulnerability does not affect any currently supported Red Hat product. This assessment may evolve based on further analysis and discovery. For more information about this vulnerability and the products it affects, please see the linked references.

Mitigation

Disable the form autofill feature in Epiphany preferences, or ensure that sensitive personal and financial information is not stored in the autofill settings. Avoid using autofill on untrusted websites.

Understanding the Weakness (CWE)

Access Control

Technical Impact: Bypass Protection Mechanism

Acknowledgements

Upstream acknowledges Fernando Munoz as the original reporter.

Frequently Asked Questions

Want to get errata notifications? Sign up here.