CVE-2026-12348: Arc Search Android Address Bar Spoofing Vulnerability
Arc Search for Android contains an address bar spoofing vulnerability that allows attackers to display a legitimate domain name in the browser's address bar while simultaneously rendering malicious content underneath. This classic phishing vector tricks users into trusting the displayed domain and interacting with attacker-controlled forms, links, or scripts. The vulnerability requires user interaction (clicking or navigating) but no special privileges, making it a practical threat to any Arc Search user on Android.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 7.4 HIGH · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N
- Weaknesses (CWE)
- CWE-1021
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-06-17 / 2026-06-17
NVD description (verbatim)
Address bar spoofing in Arc Search for Android allows a remote attacker to display a trusted domain in the address bar while rendering attacker-controlled content, enabling phishing.
1 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
The vulnerability stems from improper validation or rendering logic in Arc Search's address bar implementation. An attacker can craft a specially designed webpage or redirect sequence that causes the browser to display one domain in the address bar (typically a trusted site) while the DOM and visual content rendered to the user originates from attacker-controlled sources. This exploits a disconnect between the security indicator (the address bar) and the actual content origin, classified under CWE-1021 (Improper Restriction of Rendered UI Layers or Frames). The attack surface is network-based with no authentication required, though successful exploitation depends on user interaction—typically opening a malicious link or visiting an attacker's site.
Business impact
Users of Arc Search on Android are at elevated risk of credential theft and social engineering attacks. An attacker can craft convincing phishing pages that appear to originate from banks, payment processors, email providers, or other sensitive services. Because the address bar—a primary trust signal—shows a legitimate domain, users are more likely to enter credentials, approve sensitive actions, or download malware. For organizations with BYOD policies or employees using Arc Search for work, this vulnerability can lead to account compromise, data exfiltration, and lateral movement into corporate networks. The high CVSS score (7.4) reflects the integrity impact and broad attack surface, though availability is not affected.
Affected systems
Arc Search for Android is the confirmed affected product. The vendor_products field in the source data is empty, so no specific version ranges are documented in this intelligence record. Users should verify affected versions directly with the Arc Search vendor advisory and check whether their installed version matches the patched or vulnerable range. The vulnerability does not affect Arc Search on other platforms (iOS, desktop) unless independently verified.
Exploitability
Exploitability is straightforward and does not require advanced technical skill. An attacker simply hosts a malicious page or crafts a redirect that triggers the address bar spoofing behavior, then distributes the link via email, SMS, social media, or advertisements. No zero-day exploit code or special tools are needed. The barrier to exploitation is social engineering—convincing a user to click the link—rather than technical complexity. CVSS assigns a Low Attack Complexity (AC:L), confirming that weaponization is practical. The vulnerability is not currently tracked in the CISA Known Exploited Vulnerabilities (KEV) catalog, but lack of KEV status does not indicate low real-world risk; it may reflect recency or reporting lag.
Remediation
Users should update Arc Search to the patched version released by the vendor. Organizations should communicate this update to all employees and BYOD users, prioritizing those who access sensitive accounts or systems via mobile browsers. In the interim, users can reduce risk by carefully inspecting the address bar before entering credentials, enabling additional security features (e.g., two-factor authentication), and avoiding clicking suspicious links. Security teams may consider blocking known malicious Arc Search redirect domains or monitoring for phishing campaigns targeting this vector.
Patch guidance
Consult the official Arc Search vendor advisory for the specific patched version number and release date. Update through the Google Play Store or your device management platform if deploying Arc Search across an organization. Verify the update has been installed by checking the app version in device settings. If automatic updates are not enabled, manually trigger an update check in the Play Store. Test the patched version against known phishing indicators to confirm the address bar spoofing has been remediated.
Detection guidance
Monitor for users reporting unexpected content or domains loaded in Arc Search, particularly in combination with credential entry attempts. Network-level detection is limited because the attack is client-side; however, tracking inbound phishing emails or SMS messages that distribute Arc Search links to spoofed domains can provide early warning. Endpoint detection tools may flag suspicious Arc Search process behavior if it loads resources from mismatched origins, though signature-based detection of this vulnerability is challenging without vendor IOCs. User education and reporting of suspicious behavior remain the most practical detection mechanisms.
Why prioritize this
This vulnerability warrants prompt remediation because it directly enables phishing at scale with minimal attacker effort. The HIGH CVSS score, combined with broad attack surface (all Android Arc Search users), high integrity impact (credential theft), and low exploitability barrier, makes it an attractive target for mass phishing campaigns. Unlike vulnerabilities requiring complex exploitation chains or specialized access, this can be weaponized immediately upon discovery. Organizations with BYOD policies or heavy mobile browser usage should prioritize patching.
Risk score, explained
CVSS 7.4 (HIGH) reflects: Network-based attack vector (AV:N) with no authentication required (PR:N) and low attack complexity (AC:L), making rapid exploitation practical; User interaction required (UI:R), reducing immediate automated exploitation risk but not materially lowering threat when phishing is the attack vector; Changed scope (S:C), as rendering attacker content in a trusted browser context affects the security of downstream applications and systems; High integrity impact (I:H) due to the ability to display fabricated content and harvest credentials; No confidentiality or availability impact (C:N/A:N), as the attack does not exfiltrate data or disrupt service. The score is proportionate to the real-world phishing threat but does not inflate severity beyond the actual risk.
Frequently asked questions
How can users tell if they are affected by this vulnerability?
If you use Arc Search for Android, you are potentially affected until you update to a patched version. To check your version, open Arc Search, navigate to settings, and look for app version information. Compare it against the version range specified in the vendor advisory. If you are not on the latest version, apply updates immediately through the Google Play Store.
Can this vulnerability be exploited without user interaction?
No. The CVSS vector indicates user interaction is required (UI:R). An attacker must trick a user into opening a malicious link or visiting an attacker-controlled site. However, this is a realistic social engineering scenario, not a meaningful barrier to exploitation; phishing campaigns routinely achieve high click-through rates.
Does this affect Arc Search on iOS or desktop?
The vulnerability has been documented only for Arc Search on Android. iOS and desktop versions may have different codebases and rendering engines. However, verify this assumption against the vendor's public advisory, as address bar spoofing vulnerabilities occasionally affect multiple platforms.
What should I do if I have already entered credentials into a spoofed Arc Search page?
Immediately change your password for the affected account and enable two-factor authentication if available. Monitor your account for unauthorized access or suspicious activity. If the credentials were for a work account, alert your IT security team so they can audit access logs and watch for lateral movement. Consider whether you used the same password across other services and change those as well.
This analysis is based on vulnerability intelligence available as of the publication date (2026-06-17) and reflects the information provided in the CVE record. Vendor product version numbers, patch dates, and remediation steps are not specified in the source data and must be verified against the official Arc Search vendor advisory. SEC.co does not provide legal advice or guarantee the completeness of this intelligence. Patching and incident response decisions should be made by your organization based on your own risk assessment, system inventory, and vendor communications. The absence of KEV status does not imply low real-world risk or active exploitation. Source: NVD (public-domain), retrieved 2026-07-23. Analysis generated by SEC.co (claude-haiku-4-5).
Weaknesses (CWE)
Related vulnerabilities
- CVE-2026-0036HIGHAndroid StageCoordinator Tapjacking Privilege Escalation (CVSS 7.8 HIGH)
- CVE-2026-28577HIGHAndroid WindowManagerService Tapjacking Vulnerability – Local Privilege Escalation
- CVE-2026-0061MEDIUMAndroid WindowState Tapjacking Vulnerability – Permission Escalation Risk
- CVE-2026-10733MEDIUMGitLab CI/CD Catalog DoS Vulnerability – Patch Guidance
- CVE-2026-12322MEDIUMClickjacking in Firefox & Thunderbird Gtk Widget Component
- CVE-2026-12323MEDIUMDOM Spoofing in Firefox and Thunderbird 152
- CVE-2016-20062HIGHSQL Injection in Simply Poll 1.4.1 WordPress Plugin - Unauthenticated Data Theft
- CVE-2016-20063HIGHSQL Injection in Single Personal Message 1.0.3 – Credential & Data Theft Risk