Address Bar Spoofing in Arc Search for Android by Arc
CVE-2026-12348

7.4HIGH

What is CVE-2026-12348?

A vulnerability in Arc Search for Android enables remote attackers to manipulate the address bar, displaying a trusted domain while delivering malicious content. This effectively allows attackers to deceive users into believing they are interacting with a legitimate website, increasing the risk of phishing attempts. Users must be cautious of this exploit, as it could lead to significant security breaches and data theft.

Affected Version(s)

Arc Search Android 0

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.