Address Bar Spoof Risk in Arc Search for Android
CVE-2026-94183

7.4HIGH

Key Information:

Vendor
CVE Published:
23 September 2026

What is CVE-2026-94183?

The Arc Search application for Android prior to version 1.12.10 lacks a critical fullscreen notification feature when entering fullscreen mode while operating in the background. This vulnerability can be exploited by remote attackers through specially crafted websites, allowing them to present misleading UI elements. Users may be deceived by a spoofed address bar, which increases the risk of phishing attacks and undermines the authenticity of the content displayed.

Affected Version(s)

Arc Search Android 0 < 1.12.10

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.