GNOME 50.5 security fixes patch a gvfs CVE and Epiphany code injection
GNOME 50.5 patches gvfs CVE-2026-88924, Epiphany JavaScript injection and ZIP-slip extension flaws, plus use-after-free bugs in librsvg and GDM.
GNOME 50.5 shipped September 24 and updates 22 modules, with gvfs 1.60.3 carrying the only CVE identifier, CVE-2026-88924, which fixes socket ownership in the admin backend. Epiphany 50.6 fixes JavaScript code injection via a CSS selector in the autofill feature and a ZIP-slip path traversal in WebExtension XPI files, while 50.5 adds shell command quoting. librsvg 2.62.4 fixes a use-after-free triggered by duplicate XML entities in nested XInclude documents, and GDM 50.3 fixes two use-after-frees, one able to crash the session during screen lock or unlock.