OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-94181

HIGH · CVSS 7.4 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

Affected versions of Arc are vulnerable to an address bar spoofing issue that enables attackers to manipulate the browser's address bar using a <select> element, potentially misleading users about the origin of the content displayed. This vulnerability poses a significant risk as it can facilitate phishing attacks and other malicious activities by obscuring the true URL. Organizations using Arc should prioritize addressing this vulnerability to protect users from potential exploitation.

CVE
CVE-2026-94181
Severity
HIGH
CVSS
7.4
EPSS
0.26%

Original NVD Description

An address bar spoofing issue in affected versions of Arc could allow an attacker to spoof the browser address bar via a <select> element that triggers requestFullscreen without displaying the fullscreen notification.