CVE-2026-94183

HIGH CVSS 3.1: 7.4 EPSS 0.20%
Updated Sep 24, 2026
Arc Search
Parameter Value
CVSS 7.4 (HIGH)
Affected Versions before 1.12.10
Type CWE-451
Vendor Arc Search
Public PoC No

Arc Search for Android before version 1.12.10 does not display a fullscreen notification when a page enters fullscreen mode while the app is running in the background. A remote attacker can exploit this via a specially crafted website to render fake UI elements, such as a spoofed address bar, misleading the user about the origin of displayed content and increasing the risk of phishing.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
Required
User action required

Impact Assessment

Confidentiality
None
No data leak
Integrity
High
Complete data modification
Availability
None
No disruption

CVSS Vector v3.1

Weakness Type (CWE)