CVE-2026-94183

Summary

Arc Search for Android before version 1.12.10 does not display a fullscreen notification when a page enters fullscreen mode while the app is running in the background. A remote attacker can exploit this via a specially crafted website to render fake UI elements, such as a spoofed address bar, misleading the user about the origin of displayed content and increasing the risk of phishing.

Affected Software

VendorProductVersion RangeStatus
The Browser Company of New YorkArc Search0 < 1.12.10affected

Weaknesses

  • CWE-451: CWE-451

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References