Impact
The flaw allows a malicious web page to present a forged address bar by spinning a <select> element that triggers the browser to request fullscreen without showing the usual notification. Based on the description, it is inferred that a spoofed address bar could mislead users into believing they are in a trusted context, potentially exposing them to phishing or other UI‑spoofing attacks. This weakness exploits a misuse of the Fullscreen API, catalogued by CWE‑451.
Affected Systems
Detected in Arc browser from The Browser Company of New York. The advisory does not list specific version ranges, so any installation of Arc that has not applied the latest security patch may be vulnerable.
Risk and Exploitability
The CVSS score of 7.4 indicates a high severity. Because the EPSS score is not available, exploitation probability is unknown. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is client‑side; an attacker must host a malicious page or otherwise persuade a victim to load a crafted <select> element. Successful exploitation requires user interaction to trigger fullscreen, resulting in a spoofed address bar and covert fullscreen takeover, with a high potential for credential theft or phishing.
OpenCVE Enrichment