CVE-2026-94183: Address bar spoofing risk in affected Android versions of Arc Search
Arc Search for Android before version 1.12.10 does not display a fullscreen notification when a page enters fullscreen mode while the app is running in the background. A remote attacker can exploit this via a specially crafted website to render fake UI elements, such as a spoofed address bar, misleading the user about the origin of displayed content and increasing the risk of phishing.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Arc Search for Androidto a version that resolves this vulnerability.Fixed in 1.12.10
Event History
Frequently Asked Questions
Which installations are affected?
Arc Search for Android versions before 1.12.10 are affected. The issue occurs when a webpage enters fullscreen mode while the app is running in the background.
What does an attacker need to exploit this issue?
An attacker needs to get a user to visit a specially crafted website and interact with its misleading fullscreen content. No attacker privileges are required, but user interaction is required.
What is the practical impact?
A malicious page can render fake interface elements, including a spoofed address bar, after the app returns from the background. This can mislead users about the origin of content and facilitate phishing.
What should teams do to remediate the issue?
Update Arc Search for Android to version 1.12.10 or later. The provided data does not identify a workaround for installations that cannot be updated immediately.