CVE-2025-3839CWE-356

Epiphany: insecure external protocol invocation in epiphany

High · published January 23, 2026

CVSS v3.1
8.0
EPSS
0%
Percentile
33.5
In the wild
Unconfirmed
What it is

⚡ A design flaw in Epiphany is like a sly magician inviting you to a show, only for the trick to go horribly wrong! 🎩 Think of Epiphany as a concierge at a hotel, directing guests to external services with a friendly smile. But what if that concierge inadvertently hands guests a key to a secret room full of chaos, allowing any unwelcome entity to step right through? If exploited, an attacker could potentially execute arbitrary code on your device, making it an open invitation to compromise sensitive data or take control of your system. With no proper warnings in place, users might unknowingly grant access, opening the floodgates to a world of trouble!

Put simply

Think of Epiphany as a concierge at a hotel, directing guests to external services with a friendly smile. But what if that concierge inadvertently hands guests a key to a secret room full of chaos, allowing any unwelcome entity to step right through? This vulnerability arises from Epiphany's inability to properly warn users when it opens external URL handlers, allowing attackers to exploit vulnerabilities in those handlers for potential code execution on the client's machine.

What to do

If exploited, an attacker could potentially execute arbitrary code on your device, making it an open invitation to compromise sensitive data or take control of your system. With no proper warnings in place, users might unknowingly grant access, opening the floodgates to a world of trouble! To safeguard against this, update to the latest version of Epiphany as soon as a patch is available, and consider implementing stricter controls over which external applications are allowed to be opened. Regularly audit your external URL handler configurations for security risks as well! You’ve got this! Stay vigilant and keep your systems secure. 🛡️

The record
Technical detail
CVSS v3.1
8.0 · HIGH
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N
CVSS v4.0
Not supplied
EPSS
0.00402 · 33.5th percentile
Weakness
CWE-356 · Product UI does not Warn User of Unsafe Actions
Published
2026-01-23T03:55Z
EPSS history
Timeline
  • 23 JAN 03:55Z
    Epiphany: insecure external protocol invocation in epiphany
    cvelistv5