CVE-2026-18534: Address bar spoofing risk in affected iOS versions of Arc Search
ArcSearch for iOS versions prior to 1.48.0 could keep the address bar hidden after a page-initiated scroll, allowing attacker-controlled content to imitate browser interface elements and increasing spoofing risk.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Arc Search for iOSto a version that resolves this vulnerability.Fixed in 1.48.0
Event History
Frequently Asked Questions
Who is exposed to this issue?
Users of Arc Search for iOS versions earlier than 1.48.0 are affected when they visit a page that triggers the relevant scroll behavior. Exploitation requires the user to interact with attacker-controlled web content.
What can an attacker do if exploitation succeeds?
An attacker can use the hidden address bar state to make page content resemble browser interface elements, increasing the likelihood of convincing URL or browser-chrome spoofing. The provided information does not indicate direct confidentiality or availability impact.
What is the remediation?
Update Arc Search for iOS to version 1.48.0 or later. The issue affects versions prior to 1.48.0.