CVE-2026-18534 PUBLISHED

Address bar spoofing risk in affected iOS versions of Arc Search

Assigner: BCNY
Reserved: 31.07.2026 Published: 18.08.2026 Updated: 18.08.2026

ArcSearch for iOS versions prior to 1.48.0 could keep the address bar hidden after a page-initiated scroll, allowing attacker-controlled content to imitate browser interface elements and increasing spoofing risk.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N
CVSS Score: 7.4

Product Status

Vendor The Browser Company of New York
Product ArcSearch
Versions Default: unaffected
  • affected from 0 to 1.48.0 (excl.)

References

Problem Types

  • CWE-1021 Improper restriction of rendered UI layers or frames CWE

Impacts

  • CAPEC-148 Content Spoofing