Executive brief
Arc Search is a mobile web browser for iOS devices. This vulnerability allows attackers to hide the address bar during page scrolling and then display a fake address bar showing a different website, tricking users into thinking they're visiting a legitimate site when they're actually on a malicious one. This increases the risk of phishing and credential theft.
Technical details
The vulnerability is an address bar spoofing issue (UI redressing) in Arc Search for iOS versions prior to 1.48.0. The root cause is improper handling of the address bar visibility state after page-initiated scrolling; an attacker-controlled site can prevent the address bar from reappearing and then render a fake address bar overlay showing a different domain. The attack requires user interaction (page scrolling) but no authentication. An attacker gains the ability to convincingly spoof the browser UI and increase phishing/spoofing risk. The fix is available in version 1.48.0 and later.
Affected products
- The Browser Company Arc Search prior to 1.48.0
Timeline
- 2026-08-18: disclosed
- 2026-08-18: patched: Fix available in version 1.48.0