Description
An address bar spoofing issue in affected versions of Arc could allow an attacker to spoof the browser address bar via a <select> element that triggers requestFullscreen without displaying the fullscreen notification.
Published: 2026-09-23
Score: 7.4 High
EPSS: n/a
KEV: No
Impact: Browser address bar spoofing via a <select> element that bypasses fullscreen notification
Action: Patch Immediately
AI Analysis

Impact

The flaw allows a malicious web page to present a forged address bar by spinning a <select> element that triggers the browser to request fullscreen without showing the usual notification. Based on the description, it is inferred that a spoofed address bar could mislead users into believing they are in a trusted context, potentially exposing them to phishing or other UI‑spoofing attacks. This weakness exploits a misuse of the Fullscreen API, catalogued by CWE‑451.

Affected Systems

Detected in Arc browser from The Browser Company of New York. The advisory does not list specific version ranges, so any installation of Arc that has not applied the latest security patch may be vulnerable.

Risk and Exploitability

The CVSS score of 7.4 indicates a high severity. Because the EPSS score is not available, exploitation probability is unknown. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is client‑side; an attacker must host a malicious page or otherwise persuade a victim to load a crafted <select> element. Successful exploitation requires user interaction to trigger fullscreen, resulting in a spoofed address bar and covert fullscreen takeover, with a high potential for credential theft or phishing.

Generated by OpenCVE AI on September 23, 2026 at 21:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Arc browser to the latest version released by The Browser Company of New York.
  • Configure the browser or use a trusted extension to disable or block the requestFullscreen API for <select> elements until a vendor fix is applied.
  • Enable any built‑in policies that enforce fullscreen notifications, ensuring that every fullscreen request presents the expected cue to the user.

Generated by OpenCVE AI on September 23, 2026 at 21:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 23 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
Description An address bar spoofing issue in affected versions of Arc could allow an attacker to spoof the browser address bar via a <select> element that triggers requestFullscreen without displaying the fullscreen notification.
Title Address Bar Spoof Risk; Missing Fullscreen Notification via Select Element
Weaknesses CWE-451
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: BCNY

Published:

Updated: 2026-09-23T19:35:35.801Z

Reserved: 2026-09-21T00:50:04.410Z

Link: CVE-2026-94181

cve-icon Vulnrichment

Updated: 2026-09-23T19:35:33.654Z

cve-icon NVD

Status : Received

Published: 2026-09-23T19:19:48.763

Modified: 2026-09-23T20:17:23.800

Link: CVE-2026-94181

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T21:15:09Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information