CVE-2025-14809

HIGH

ArcSearch <1.12.6 - CSRF

Title source: llm
STIX 2.1

Description

ArcSearch for Android versions prior to 1.12.6 could display a different domain in the address bar than the content being shown, enabling address bar spoofing after user interaction via crafted web content.

Scores

CVSS v3 7.4
EPSS 0.0005
EPSS Percentile 15.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-1021
Status published
Products (1)
The Browser Company of New York/ArcSearch < 1.12.6
Published Dec 19, 2025
Tracked Since Feb 18, 2026