CVE-2026-94183: CWE-451 in The Browser Company of New York Arc Search
Arc Search for Android before version 1.12.10 does not display a fullscreen notification when a page enters fullscreen mode while the app is running in the background. A remote attacker can exploit this via a specially crafted website to render fake UI elements, such as a spoofed address bar, misleading the user about the origin of displayed content and increasing the risk of phishing.
AI Analysis
Technical Summary
CVE-2026-94183 is a vulnerability in The Browser Company of New York's Arc Search for Android prior to version 1.12.10. The flaw involves the app's failure to display a fullscreen notification when a webpage enters fullscreen mode while the app is backgrounded. This can be exploited remotely via a specially crafted website to render deceptive UI elements like a fake address bar, misleading users about the content's origin and facilitating phishing attacks.
Potential Impact
The vulnerability enables remote attackers to spoof UI elements, such as the address bar, which can mislead users about the legitimacy of displayed content. This increases the risk of phishing attacks by making malicious websites appear trustworthy. There is no impact on confidentiality or availability reported, but the integrity of user interface trust is compromised.
Mitigation Recommendations
A fix is available in Arc Search for Android version 1.12.10 and later. Users and administrators should update to version 1.12.10 or newer to remediate this vulnerability.
CVE-2026-94183: CWE-451 in The Browser Company of New York Arc Search
Description
Arc Search for Android before version 1.12.10 does not display a fullscreen notification when a page enters fullscreen mode while the app is running in the background. A remote attacker can exploit this via a specially crafted website to render fake UI elements, such as a spoofed address bar, misleading the user about the origin of displayed content and increasing the risk of phishing.
CVSS v3.1
Score 7.4high
Affected software
The Browser Company of New York
Arc Search
pkg:github/thebrowsercompany/arc-searchRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-94183 is a vulnerability in The Browser Company of New York's Arc Search for Android prior to version 1.12.10. The flaw involves the app's failure to display a fullscreen notification when a webpage enters fullscreen mode while the app is backgrounded. This can be exploited remotely via a specially crafted website to render deceptive UI elements like a fake address bar, misleading users about the content's origin and facilitating phishing attacks.
Potential Impact
The vulnerability enables remote attackers to spoof UI elements, such as the address bar, which can mislead users about the legitimacy of displayed content. This increases the risk of phishing attacks by making malicious websites appear trustworthy. There is no impact on confidentiality or availability reported, but the integrity of user interface trust is compromised.
Mitigation Recommendations
A fix is available in Arc Search for Android version 1.12.10 and later. Users and administrators should update to version 1.12.10 or newer to remediate this vulnerability.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- BCNY
- Date Reserved
- 2026-09-21T01:12:48.672Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ab42d0ef7a7c541063f0e70
Added to database: 09/23/2026, 19:48:30 UTC
Last enriched: 09/23/2026, 20:02:39 UTC
Last updated: 09/24/2026, 04:06:50 UTC
Views: 15
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.