Address Bar Spoofing in Arc from Arc Inc.
CVE-2026-94181

7.4HIGH

Key Information:

Status
Vendor
CVE Published:
23 September 2026

What is CVE-2026-94181?

A security concern has been identified in the Arc browser, wherein an attacker can exploit a flaw involving the element to spoof the browser's address bar. This issue arises when the requestFullscreen is triggered without the standard fullscreen notification. As a result, users may not be aware that they are interacting with a spoofed interface, potentially leading to phishing attacks or other malicious activities. It is crucial for users to ensure they are using the latest version of Arc to mitigate this risk.

Affected Version(s)

Arc MacOS 0 < 1.159.0

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.