CVE-2026-2378

7.4

The Browser Company of New York · ArcSearch for Android

ArcSearch for Android versions before 1.12.7 are vulnerable to address bar spoofing, allowing attackers to display a deceptive domain while presenting malicious web content to the user.

Executive summary

A high-severity address bar spoofing vulnerability in ArcSearch for Android may allow attackers to deceive users by displaying a fraudulent domain while serving malicious content.

Vulnerability

This vulnerability, categorized as CWE-1021, occurs due to the improper restriction of rendered UI layers, allowing unauthenticated attackers to manipulate the address bar display following specific user interaction with crafted web content.

Business impact

The ability to spoof the domain displayed in the address bar poses a significant risk to user trust and security. By misrepresenting the source of web content, an attacker can facilitate sophisticated phishing campaigns, credential harvesting, or the delivery of malicious payloads, potentially leading to unauthorized data access or account compromise. Given the CVSS score of 7.4, this vulnerability is considered a high-risk issue that could undermine the integrity of the browsing experience.

Remediation

Immediate Action: Update the ArcSearch application to version 1.12.7 or later via the official Android application store to resolve the underlying UI rendering flaw.

Proactive Monitoring: Security teams should monitor mobile device management logs for reports of suspicious browsing activity or user complaints regarding unexpected redirects and domain mismatches.

Compensating Controls: While no direct technical compensating control exists for this client-side flaw, users should be educated on the risks of interacting with untrusted links and verifying the legitimacy of web content through secondary channels.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The risk posed by address bar spoofing is substantial, as it directly targets user perception to facilitate malicious activity. Administrators and individual users are urged to apply the version 1.12.7 update immediately to ensure the integrity of the browser UI is restored. Failure to patch leaves users susceptible to targeted phishing and social engineering attacks that appear to originate from legitimate domains.

More The Browser Company of New York CVEs

Sources