Skip to content

Security1 publisher2 min readPublished

GNOME 50.5 closes an Epiphany autofill injection first fixed upstream 42 days earlier

The release updates 22 modules and includes a single CVE identifier, in gvfs, described in one changelog line with no severity score. The Epiphany, librsvg and GDM fixes reach users when their distribution rebuilds.

The Watch · Security desk

What happened

  • The GNOME Release Team shipped GNOME 50.5 on September 24, patching a CVE in the gvfs file system layer, a JavaScript injection flaw in the Epiphany browser and a use-after-free in the librsvg image library.
  • GDM 50.3 fixes two use-after-free bugs, one able to crash the whole user session during screen lock or unlock, and repairs a regression that had broken authentication on systemd.
  • The release updates 22 modules in all, including librsvg, GNOME Shell, libgsf and libsecret.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure For an operator, the date that counts is the distribution rebuild: every machine running GNOME 50 stays reachable through Epiphany, librsvg and gvfs until its distribution rebuilds and ships the packages.
  • capability A crafted WebExtension XPI that writes outside its install directory turns a user-approved extension install into arbitrary file placement on disk.
  • decision Fleets that rendered untrusted SVG or ran Epiphany through the 42-day window have to decide whether to treat that period as unmonitored.

gvfs 1.60.3 carries the release's only CVE identifier, CVE-2026-88924, and the fix is an ordering change: the admin backend now sets ownership on its socket before creating it [10][11]. The changelog is one line, with no severity score [12].

Epiphany moves from 50.4 to 50.6 here, taking in two August builds [5]. Version 50.6, dated August 13, fixes JavaScript code injection through a CSS selector in the autofill feature and a path traversal flaw in WebExtension XPI files that upstream labels ZIPSLIP [6]. The two paths differ in what they need. The extension bug requires a user to install a crafted package, after which the archive writes files outside the folder meant to hold it [7]. The autofill bug is in the browser's own handling of a CSS selector [6]. Version 50.5 added quoting to command line input before Epiphany hands it to a shell [8].

Epiphany 50.6 was dated August 13 and GNOME 50.5 shipped on September 24, so those two fixes were public for 42 days before they reached the module bundle most distributions track [20]. For a fleet, the exposure ends later still, when the distribution ships the rebuilt packages to users who browse with Epiphany, view SVG images through librsvg or reach files through gvfs [3].

librsvg 2.62.4 fixes a use-after-free, and duplicate XML entities in nested XInclude documents triggered it [13]. Any application that renders an untrusted SVG through librsvg inherits that one. The same release updates two Rust dependencies for advisories RUSTSEC-2026-0187 and RUSTSEC-2026-0204 [14].

The lock screen got attention too. GDM 50.3 fixes two use-after-free bugs, one of which could crash the whole user session during screen lock or unlock [15], and repairs a regression in which an earlier security fix broke authentication on systemd [16]. GNOME Shell 50.5 now refuses to unlock the screen after a screen time limit is reached, cancels mount password dialogs when the screen locks, and validates serialized image data before creating a pixbuf [17].

Two file-handling libraries were hardened, and neither fix has an identifier [10]: libgsf 1.14.59 guards its OLE2 loader against runaway recursion and fixes zip reads on corrupted streams, and libsecret's file backend gains file locking to stop concurrent writes from racing [18][19]. "All operating systems shipping GNOME 50 are encouraged to upgrade," the GNOME Release Team wrote [4].

What to watch

  • Whether distributions shipping GNOME 50 publish rebuilt packages, and how many days after September 24 they land.
  • A severity score or vulnerability database entry for CVE-2026-88924 that lets administrators rank the gvfs socket fix.
  • Any public proof of concept for the Epiphany autofill injection, which would move it from a changelog line to a live exploit.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories