GNOME 50.5, released September 24, updates 22 modules and patches a gvfs CVE, an Epiphany JavaScript injection, and a librsvg use-after-free. The release team encouraged all operating systems shipping GNOME 50 to upgrade, noting that users remain exposed until their distribution ships the new packages.
Epiphany jumps from 50.4 to 50.6, picking up two August versions. Version 50.6 fixes JavaScript code injection through a CSS selector in the autofill feature and a ZIP slip path traversal in WebExtension XPI files, where a crafted archive could write files outside the intended folder. Version 50.5 adds quoting to command-line input before handing it to a shell, and the two versions also fix crashes in the password manager and on invalid bookmark imports.
gvfs 1.60.3 carries the only CVE identifier in the release notes, CVE-2026-88924, with a one-line changelog entry about socket ownership and no severity score. librsvg 2.62.4 fixes a use-after-free triggered by duplicate XML entities in nested XInclude documents and updates two Rust dependencies. GDM 50.3 fixes two use-after-free bugs, one of which could crash the whole user session during screen lock or unlock, and repairs a regression that broke authentication on systemd.
GNOME Shell 50.5 now refuses to unlock the screen after a screen time limit is reached, cancels mount password dialogs when the screen locks, and validates serialized image data before creating a pixbuf. libgsf and libsecret also harden file handling, with libgsf guarding its OLE2 loader against runaway recursion and libsecret adding file locking to prevent concurrent writes from racing.