CVE-2026-12348: Address Bar Spoofing in Arc Search for Android (window.open race condition)
Published Jun 16, 2026
·Updated
Address bar spoofing in Arc Search for Android allows a remote attacker to display a trusted domain in the address bar while rendering attacker-controlled content, enabling phishing.
Affected Software
1 affected component
The Browser Company Arc Search for Android
Event History
Jun 16, 2026
CVE Published
via MITRE·07:54 PM
Data Sourced
via MITRE·07:54 PM
DescriptionSeverityWeakness
Jun 17, 2026
Data Sourced
via NVD·10:14 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-12348?
CVE-2026-12348 has a severity score of 7.4, indicating a high risk.
2
How does CVE-2026-12348 exploit address bar spoofing?
CVE-2026-12348 allows attackers to display a trusted domain in the address bar while showing malicious content.
3
Who is affected by CVE-2026-12348?
CVE-2026-12348 affects users of Arc Search for Android from The Browser Company.
4
What are the potential consequences of exploiting CVE-2026-12348?
Exploitation of CVE-2026-12348 could lead to phishing attacks that compromise user credentials.
5
How can I protect myself from CVE-2026-12348?
To protect against CVE-2026-12348, users should ensure they are using the latest version of Arc Search for Android.