Description
Arc Search for Android before version 1.12.10 does not display a fullscreen notification when a page enters fullscreen mode while the app is running in the background. A remote attacker can exploit this via a specially crafted website to render fake UI elements, such as a spoofed address bar, misleading the user about the origin of displayed content and increasing the risk of phishing.
Published: 2026-09-23
Score: 7.4 High
EPSS: n/a
KEV: No
Impact: User interface spoofing enabling phishing
Action: Apply patch
AI Analysis

Impact

Arc Search for Android before version 1.12.10 fails to display a fullscreen notification when the app enters fullscreen mode while it is in the background. A malicious website can trigger such fullscreen mode, allowing the attacker to render deceptive UI elements—including a counterfeit address bar—under the guise of legitimate content. This directly increases the risk of phishing by misleading users about the true origin of the displayed information. The flaw is a type of Improper Notification Bypass, identified as CWE-451.

Affected Systems

The Browser Company of New York’s Arc Search application for Android, versions prior to 1.12.10, is affected.

Risk and Exploitability

The CVSS score of 7.4 classifies the vulnerability as high severity, while the EPSS score is not available and the entry is not listed in CISA’s KEV catalog. An attacker can gain advantage by crafting a website that loads in Arc Search when the app is in the background, exploiting the missing fullscreen notification to inject spoofed UI elements. The vulnerability therefore poses a significant phishing risk in environments where Arc Search is used normally.

Generated by OpenCVE AI on September 23, 2026 at 21:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Arc Search on all Android devices to version 1.12.10 or later.
  • Close the Arc Search app or prevent it from running in the background when not actively used.
  • Watch for unexpected fullscreen UI elements after returning from background; treat them with suspicion until the app is updated.

Generated by OpenCVE AI on September 23, 2026 at 21:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared The Browsercompany Of New York
The Browsercompany Of New York arcsearch
Vendors & Products The Browsercompany Of New York
The Browsercompany Of New York arcsearch

Wed, 23 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 23 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Description Arc Search for Android before version 1.12.10 does not display a fullscreen notification when a page enters fullscreen mode while the app is running in the background. A remote attacker can exploit this via a specially crafted website to render fake UI elements, such as a spoofed address bar, misleading the user about the origin of displayed content and increasing the risk of phishing.
Title Address bar spoofing risk in affected Android versions of Arc Search
Weaknesses CWE-451
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N'}


Subscriptions

The Browsercompany Of New York Arcsearch
cve-icon MITRE

Status: PUBLISHED

Assigner: BCNY

Published:

Updated: 2026-09-23T19:31:48.867Z

Reserved: 2026-09-21T01:12:48.672Z

Link: CVE-2026-94183

cve-icon Vulnrichment

Updated: 2026-09-23T19:31:46.336Z

cve-icon NVD

Status : Received

Published: 2026-09-23T20:17:23.907

Modified: 2026-09-23T20:17:23.907

Link: CVE-2026-94183

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T21:45:02Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information