CVE-2025-3839
A flaw was found in Epiphany, a tool that allows websites to open external URL handler applications with minimal user interaction. This design can be misused to exploit vulnerabilities within those handlers, making them appear remotely exploitable. The browser fails to properly warn or gate this action, resulting in potential code execution on the client device via trusted UI behavior.
Scoring
- Severity
- HIGH
- CVSS base score
- 8
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N
- EPSS probability
- 0.40%
- CWE
- CWE-356
- Published
- 2026-01-23
- Last modified
- 2026-03-12
Weakness type
Related vulnerabilities
- CVE-2026-0777 — Xmind Attachment Insufficient UI Warning Remote Code Execution Vulnerability
- CVE-2026-25805 — Zed does not show Parameter Values for MCP Tool Calls. Users cannot detect tool poisoning.
- CVE-2025-14414 — Soda PDF Desktop Word File Insufficient UI Warning Remote Code Execution Vulnerability
- CVE-2025-14415 — Soda PDF Desktop Launch Insufficient UI Warning Remote Code Execution Vulnerability
- CVE-2025-14412 — Soda PDF Desktop XLS File Insufficient UI Warning Remote Code Execution Vulnerability
- CVE-2025-14418 — pdfforge PDF Architect XLS File Insufficient UI Warning Remote Code Execution Vulnerability
- CVE-2025-14417 — pdfforge PDF Architect Launch Insufficient UI Warning Remote Code Execution Vulnerability
- CVE-2025-14416 — pdfforge PDF Architect DOC File Insufficient UI Warning Remote Code Execution Vulnerability