Impact
Arc Search for Android before version 1.12.10 fails to display a fullscreen notification when the app enters fullscreen mode while it is in the background. A malicious website can trigger such fullscreen mode, allowing the attacker to render deceptive UI elements—including a counterfeit address bar—under the guise of legitimate content. This directly increases the risk of phishing by misleading users about the true origin of the displayed information. The flaw is a type of Improper Notification Bypass, identified as CWE-451.
Affected Systems
The Browser Company of New York’s Arc Search application for Android, versions prior to 1.12.10, is affected.
Risk and Exploitability
The CVSS score of 7.4 classifies the vulnerability as high severity, while the EPSS score is not available and the entry is not listed in CISA’s KEV catalog. An attacker can gain advantage by crafting a website that loads in Arc Search when the app is in the background, exploiting the missing fullscreen notification to inject spoofed UI elements. The vulnerability therefore poses a significant phishing risk in environments where Arc Search is used normally.
OpenCVE Enrichment