CVE-2025-13132
7.4The Browser Company of New York · Arc Browser (Dia)
A UI spoofing vulnerability in Arc Browser allows a site to enter fullscreen mode without a notification, enabling the rendering of fake UI elements to deceive users.
Executive summary
A critical UI spoofing vulnerability in the Arc Browser allows malicious sites to bypass fullscreen notifications to facilitate credential theft or phishing via fake address bars.
Vulnerability
This flaw, categorized as Improper Restriction of Rendered UI Layers or Frames (CWE-1021), allows an unauthenticated remote attacker to trigger a fullscreen state without the required user notification toast. By suppressing this visual indicator, an attacker can overlay deceptive interface components to impersonate legitimate websites.
Business impact
The ability to present a spoofed user interface poses a significant risk to organizational security, as it facilitates sophisticated phishing attacks and credential harvesting. While the CVSS score of 7.4 reflects a high impact on integrity, the primary danger lies in the potential for users to be misled into entering sensitive information into illegitimate, attacker-controlled UI layers.
Remediation
Immediate Action: Update the Arc Browser to version 1.6.0 or later immediately to ensure the fullscreen notification mechanism is correctly enforced.
Proactive Monitoring: Security teams should monitor endpoint logs for browser-related anomalies and educate users on identifying signs of browser spoofing, such as inconsistencies in standard UI elements.
Compensating Controls: Deploy endpoint protection solutions that can detect and block navigation to known malicious domains, providing a defense-in-depth layer against sites attempting to exploit UI rendering flaws.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the nature of this vulnerability as a mechanism for deceptive UI manipulation, the risk of exploitation increases if users are not protected by the latest security patches. Organizations should prioritize updating the Arc Browser across all managed workstations to version 1.6.0 to restore essential browser security notifications and prevent potential phishing success.