๐Ÿ” CVE Alert

CVE-2026-94183

HIGH 7.4

Address bar spoofing risk in affected Android versions of Arc Search

CVSS Score
7.4
EPSS Score
0.0%
EPSS Percentile
0th

Arc Search for Android before version 1.12.10 does not display a fullscreen notification when a page enters fullscreen mode while the app is running in the background. A remote attacker can exploit this via a specially crafted website to render fake UI elements, such as a spoofed address bar, misleading the user about the origin of displayed content and increasing the risk of phishing.

CWE CWE-451
Vendor the browser company of new york
Product arc search
Published Sep 23, 2026
Last Updated Sep 23, 2026
Stay Ahead of the Next One

Get instant alerts for the browser company of new york arc search

Be the first to know when new high vulnerabilities affecting the browser company of new york arc search are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
None
Integrity
High
Availability
None

Affected Versions

The Browser Company of New York / Arc Search
0 < 1.12.10

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
hackerone.com: https://hackerone.com/reports/3572193 arc.net: https://arc.net/security/bulletins#cve-2026-94183-address-bar-spoof-risk-missing-fullscreen-notification-on-return-from-background