CVE-2026-12348
Received Received - Intake
Address Bar Spoofing Vulnerability in Arc Search for Android

Publication date: 2026-06-17

Last updated on: 2026-06-17

Assigner: BCNY

Description
Address bar spoofing in Arc Search for Android allows a remote attacker to display a trusted domain in the address bar while rendering attacker-controlled content, enabling phishing.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-17
Last Modified
2026-06-17
Generated
2026-06-17
AI Q&A
2026-06-17
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Currently, no data is known.
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1021 The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain, which can lead to user confusion about which interface the user is interacting with.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability is an address bar spoofing issue in Arc Search for Android. It allows a remote attacker to make the address bar display a trusted domain name while actually showing content controlled by the attacker.

This means users can be tricked into believing they are visiting a legitimate website when they are not, which can be used to facilitate phishing attacks.

Impact Analysis

The vulnerability can impact you by enabling attackers to perform phishing attacks. Since the address bar shows a trusted domain, users may be deceived into entering sensitive information such as passwords, credit card numbers, or other personal data into malicious sites.

This can lead to identity theft, financial loss, or unauthorized access to your accounts.

Compliance Impact

This vulnerability enables address bar spoofing in Arc Search for Android, allowing attackers to display a trusted domain while showing attacker-controlled content, which facilitates phishing attacks.

Such phishing capabilities can lead to unauthorized disclosure or misuse of sensitive personal or health information, potentially impacting compliance with regulations like GDPR and HIPAA that require protection against unauthorized access and fraud.

Therefore, this vulnerability may increase the risk of non-compliance with these standards due to the elevated threat of phishing and information compromise.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12348. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart