Unrated severityNVD Advisory· Published Jun 16, 2026
Address Bar Spoofing in Arc Search for Android (window.open race condition)
CVE-2026-12348
Description
Address bar spoofing in Arc Search for Android allows a remote attacker to display a trusted domain in the address bar while rendering attacker-controlled content, enabling phishing.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.