ArcSearch for Android versions prior to 1.12.7 could display a different domain in the address bar than the content being shown, enabling address bar spoofing after user interaction via crafted web content.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://arc.net/security/bulletins |
|
History
Mon, 23 Mar 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
The Browsercompany Of New York
The Browsercompany Of New York arcsearch |
|
| Vendors & Products |
The Browsercompany Of New York
The Browsercompany Of New York arcsearch |
Fri, 20 Mar 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ArcSearch for Android versions prior to 1.12.7 could display a different domain in the address bar than the content being shown, enabling address bar spoofing after user interaction via crafted web content. | |
| Title | Address bar spoofing risk in ArcSearch on Android | |
| Weaknesses | CWE-1021 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: BCNY
Published:
Updated: 2026-03-20T21:16:51.942Z
Reserved: 2026-02-11T21:24:56.878Z
Link: CVE-2026-2378
No data.
Status : Received
Published: 2026-03-20T22:16:27.497
Modified: 2026-03-20T22:16:27.497
Link: CVE-2026-2378
No data.
OpenCVE Enrichment
Updated: 2026-03-23T09:52:38Z
Weaknesses