CyberRota Analysis
AI-GeneratedArc Search for Android versions prior to 1.12.10 is vulnerable to a security flaw that allows remote attackers to exploit fullscreen mode when the app is running in the background. This can lead to the display of deceptive UI elements, such as a spoofed address bar, which heightens the risk of phishing attacks. Users and organizations utilizing this app should prioritize updating to the latest version to mitigate potential security threats.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Arc Search for Android before version 1.12.10 does not display a fullscreen notification when a page enters fullscreen mode while the app is running in the background. A remote attacker can exploit this via a specially crafted website to render fake UI elements, such as a spoofed address bar, misleading the user about the origin of displayed content and increasing the risk of phishing.