Junglewise Threat Intelligence

CVE-2026-12348: The Browser Company Arc Search address bar spoofing on Android

CVE-2026-12348 · Severity: high · CVSS 7.4 · Published 2026-06-17

Executive brief

Arc Search is a mobile web browser for Android devices. A security flaw allows a malicious website to display a fake web address in the browser's address bar, making a fraudulent site appear as a legitimate, trusted domain (like a bank or email provider). This significantly increases the risk of successful phishing attacks where users are tricked into providing sensitive login credentials or personal information.

Technical details

An address bar spoofing vulnerability exists in Arc Search for Android due to improper restriction of rendered UI layers or frames (CWE-1021). By enticing a user to visit a specially crafted webpage, a remote, unauthenticated attacker can manipulate the browser's UI to display a legitimate URL while the main window renders malicious content. This bypasses the user's ability to verify the authenticity of the site via the address bar. The vulnerability is confirmed in versions up to and including 1.12.8. Exploitation requires minimal user interaction (visiting a link) and carries a high integrity impact.

Affected products

  • The Browser Company of New York Arc Search up to 1.12.8

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References