Impact
The vulnerability involves ArcSearch on iOS versions earlier than 1.48.0 permitting the address bar to be hidden after a page‑initiated scroll. This allows content loaded within the browser to mimic browser‑provided interface elements, creating a risk that users could be deceived into interacting with malicious material under the illusion that it is genuine browser content.
Affected Systems
This issue affects ArcSearch from The Browser Company of New York on iOS devices running any version of the browser before 1.48.0.
Risk and Exploitability
With a CVSS score of 7.4, the vulnerability poses a moderate‑to‑high risk. No EPSS score is publicly available, and the issue is not listed in CISA’s KEV catalog. A likely exploitation path requires the user to visit a malicious or compromised web page in the affected ArcSearch browser; the hidden address bar can then be used to present spoofed interface elements. Because the vector is user‑triggered, remediation by keeping the browser updated is the key protection.
OpenCVE Enrichment