PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-12348 The Browser Company of New York` CVE debrief

CVE-2026-12348 is a high-severity vulnerability in Arc Search for Android that allows remote attackers to display a trusted domain in the address bar while rendering attacker-controlled content, enabling phishing. This address bar spoofing vulnerability has a CVSS score of 7.4 and was published on June 17, 2026. The vulnerability is considered high severity and could be used for phishing attacks. Users of Arc Search for Android are advised to exercise caution when clicking on links from untrusted sources. The CVE record and NVD detail provide further information on this vulnerability.

Vendor
The Browser Company of New York`
Product
Arc Search
CVSS
HIGH 7.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-17
Original CVE updated
2026-06-17
Advisory published
2026-06-17
Advisory updated
2026-06-17

Who should care

Users of Arc Search for Android, security teams, and IT administrators should be aware of this vulnerability and take necessary precautions to prevent phishing attacks.

Technical summary

CVE-2026-12348 is an address bar spoofing vulnerability in Arc Search for Android that allows remote attackers to display a trusted domain in the address bar while rendering attacker-controlled content. This enables phishing attacks, which can lead to sensitive information disclosure. The vulnerability has a CVSS score of 7.4 and is considered high severity. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N.

Defensive priority

High

Recommended defensive actions

  • Update Arc Search for Android to the latest version
  • Be cautious when clicking on links from untrusted sources
  • Verify the authenticity of websites before entering sensitive information
  • Use a reputable security software to detect and prevent phishing attacks
  • Educate users on how to identify phishing attempts
  • Monitor for suspicious activity and implement incident response plans

Evidence notes

The CVE record and NVD detail provide information on this vulnerability. The CVE was published on June 17, 2026, and has a CVSS score of 7.4. The vulnerability is considered high severity.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-12348 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-12348

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-12348 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-12348

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://hackerone.com/reports/3705306

    59469e6c-7ea7-446f-8e43-06aa32c115e8

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.