CVE-2026-2378
CVE-2026-2378
7.4
HighPublished:
Last updated:
Source:59469e6c-7ea7-446f-8e43-06aa32c115e8
Analyzed
Weakness (CWE)
CVSS Vector
v3.1- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- Required
- Scope
- Changed
- Confidentiality
- None
- Integrity
- High
- Availability
- None
Description
ArcSearch for Android versions prior to 1.12.7 could display a different domain in the address bar than the content being shown, enabling address bar spoofing after user interaction via crafted web content.
References
59469e6c-7ea7-446f-8e43-06aa32c115e8
https://arc.net/security/bulletins