CVE-2026-2378
HIGHCVSS v3.1: 7.4 · EPSS: 0.0003 (8.5 percentile)
Source data as of:
At a glance
- Severity
- HIGH
- CVSS
- 7.4 v3.1 · NVD
- EPSS
- 0.0003 (8.5 percentile) · FIRST.org
- CISA KEV
- No
- Attack conditions (CVSS vector)
- NetworkNo privileges · Source: NVD Vector
- Affected vendors
- thebrowser
- Published
- 2026-03-20 · Modified: 2026-04-16
- References
- Jump to references (1)
CVSS / EPSS / KEV
Source — CVSS: NVD · EPSS: FIRST.org · KEV: CISA. Data & Sources
Description
ArcSearch for Android versions prior to 1.12.7 could display a different domain in the address bar than the content being shown, enabling address bar spoofing after user interaction via crafted web content.
References
Reference URLs as listed by NVD, grouped by a mechanical match on the link's host/pattern. Labels describe the link type only.
- Vendor advisory https://arc.net/security/bulletins