Address Bar Spoofing Risk in ArcSearch for iOS by Arc
CVE-2026-18534

7.4HIGH

Key Information:

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-18534?

ArcSearch for iOS, particularly versions prior to 1.48.0, is vulnerable to an issue where the address bar can remain hidden following a page-initiated scroll. This behavior allows malicious actors to present attacker-controlled content that can imitate browser interface elements, significantly increasing the risk of spoofing attacks. It is essential for users and administrators to update to the latest version to mitigate these risks.

Affected Version(s)

ArcSearch iOS 0 < 1.48.0

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.