OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-94183

HIGH · CVSS 7.4 EPSS 0.20% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

Arc Search for Android versions prior to 1.12.10 is vulnerable to a security flaw that allows remote attackers to exploit fullscreen mode when the app is running in the background. This can lead to the display of deceptive UI elements, such as a spoofed address bar, which heightens the risk of phishing attacks. Users and organizations utilizing this app should prioritize updating to the latest version to mitigate potential security threats.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-94183
Severity
HIGH
CVSS
7.4
EPSS
0.20%
Android

Original NVD Description

Arc Search for Android before version 1.12.10 does not display a fullscreen notification when a page enters fullscreen mode while the app is running in the background. A remote attacker can exploit this via a specially crafted website to render fake UI elements, such as a spoofed address bar, misleading the user about the origin of displayed content and increasing the risk of phishing.