CVE-2025-14809

HIGH

ArcSearch <1.12.6 - CSRF

Title source: llm

Description

ArcSearch for Android versions prior to 1.12.6 could display a different domain in the address bar than the content being shown, enabling address bar spoofing after user interaction via crafted web content.

Scores

CVSS v3 7.4
EPSS 0.0004
EPSS Percentile 11.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N

Classification

CWE
CWE-1021
Status draft

Timeline

Published Dec 19, 2025
Tracked Since Feb 18, 2026