CVE-2023-26081 (https://gitlab.gnome.org/GNOME/epiphany/-/merge_requests/1275): https://github.com/google/security-research/security/advisories/GHSA-mhhf-w9xw-pp9x In Epiphany (aka GNOME Web) through 43.0, untrusted web content can trick users into exfiltrating passwords, because autofill occurs in sandboxed contexts. Patches at above merge request, don't appear to be in any release.
This is solved in all 44.x version, as they include https://gitlab.gnome.org/GNOME/epiphany/-/commit/53363c3c8178bf9193dad9fa3516f4e10cff0ffd
Great, thanks! We've been cleaned up for this for a while now, then. All done!