CVE-2026-2378

HIGH

Address bar spoofing risk in ArcSearch on Android

Title source: cna
STIX 2.1

Description

ArcSearch for Android versions prior to 1.12.7 could display a different domain in the address bar than the content being shown, enabling address bar spoofing after user interaction via crafted web content.

Scores

CVSS v3 7.4
EPSS 0.0003
EPSS Percentile 10.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-1021
Status published
Products (2)
The BrowserCompany of New York/ArcSearch < 1.12.7
thebrowser/arc_search < 1.12.7
Published Mar 20, 2026
Tracked Since Mar 21, 2026