Description
ArcSearch for iOS versions prior to 1.48.0 could keep the address bar hidden after a page-initiated scroll, allowing attacker-controlled content to imitate browser interface elements and increasing spoofing risk.
Published: 2026-08-18
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability involves ArcSearch on iOS versions earlier than 1.48.0 permitting the address bar to be hidden after a page‑initiated scroll. This allows content loaded within the browser to mimic browser‑provided interface elements, creating a risk that users could be deceived into interacting with malicious material under the illusion that it is genuine browser content.

Affected Systems

This issue affects ArcSearch from The Browser Company of New York on iOS devices running any version of the browser before 1.48.0.

Risk and Exploitability

With a CVSS score of 7.4, the vulnerability poses a moderate‑to‑high risk. No EPSS score is publicly available, and the issue is not listed in CISA’s KEV catalog. A likely exploitation path requires the user to visit a malicious or compromised web page in the affected ArcSearch browser; the hidden address bar can then be used to present spoofed interface elements. Because the vector is user‑triggered, remediation by keeping the browser updated is the key protection.

Generated by OpenCVE AI on August 18, 2026 at 16:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade ArcSearch to version 1.48.0 or newer on all iOS devices.
  • Ensure the iOS operating system is current, as newer OS patches may affect browser rendering behavior.
  • Restrict browsing to trusted sites and avoid or limit page‑initiated scroll actions when dealing with sensitive content.

Generated by OpenCVE AI on August 18, 2026 at 16:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared The Browsercompany Of New York
The Browsercompany Of New York arcsearch
Vendors & Products The Browsercompany Of New York
The Browsercompany Of New York arcsearch

Tue, 18 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
Description ArcSearch for iOS versions prior to 1.48.0 could keep the address bar hidden after a page-initiated scroll, allowing attacker-controlled content to imitate browser interface elements and increasing spoofing risk.
Title Address bar spoofing risk in affected iOS versions of Arc Search
Weaknesses CWE-1021
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N'}


Subscriptions

The Browsercompany Of New York Arcsearch
cve-icon MITRE

Status: PUBLISHED

Assigner: BCNY

Published:

Updated: 2026-08-18T16:04:54.354Z

Reserved: 2026-07-31T20:24:59.132Z

Link: CVE-2026-18534

cve-icon Vulnrichment

Updated: 2026-08-18T16:04:51.628Z

cve-icon NVD

Status : Deferred

Published: 2026-08-18T15:16:49.667

Modified: 2026-09-03T16:41:09.297

Link: CVE-2026-18534

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T17:45:06Z

Weaknesses
  • CWE-1021

    Improper Restriction of Rendered UI Layers or Frames