ArcSearch for Android versions prior to 1.12.7 could display a different domain in the address bar than the content being shown, enabling address bar spoofing after user interaction via crafted web content.
References
History

Fri, 20 Mar 2026 21:30:00 +0000

Type Values Removed Values Added
Description ArcSearch for Android versions prior to 1.12.7 could display a different domain in the address bar than the content being shown, enabling address bar spoofing after user interaction via crafted web content.
Title Address bar spoofing risk in ArcSearch on Android
Weaknesses CWE-1021
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: BCNY

Published:

Updated: 2026-03-20T21:16:51.942Z

Reserved: 2026-02-11T21:24:56.878Z

Link: CVE-2026-2378

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-03-20T22:16:27.497

Modified: 2026-03-20T22:16:27.497

Link: CVE-2026-2378

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.