CVE-2026-2378: Address bar spoofing risk in ArcSearch on Android
Published Mar 20, 2026
·Updated
ArcSearch for Android versions prior to 1.12.7 could display a different domain in the address bar than the content being shown, enabling address bar spoofing after user interaction via crafted web content.
Affected Software
2 affected components
The Browser Company ArcSearch for Android<1.12.7
Thebrowser Arc Search Android<1.12.7
Event History
Mar 20, 2026
CVE Published
via MITRE·09:16 PM
Data Sourced
via MITRE·09:16 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-2378?
CVE-2026-2378 is classified as a medium severity vulnerability due to the potential for address bar spoofing.
2
How do I fix CVE-2026-2378?
To fix CVE-2026-2378, update ArcSearch for Android to version 1.12.7 or later.
3
What is the impact of CVE-2026-2378?
The impact of CVE-2026-2378 is that it allows an attacker to deceive users into believing they are on a legitimate website.
4
Who is affected by CVE-2026-2378?
Users running ArcSearch for Android versions prior to 1.12.7 are affected by CVE-2026-2378.
5
What is address bar spoofing in the context of CVE-2026-2378?
Address bar spoofing in CVE-2026-2378 refers to the ability of malicious content to display a misleading domain in the address bar.