PatchSiren

The Browser Company of New York CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH The Browser Company of New York CVE published 2026-08-18

CVE-2026-18534

CVE-2026-18534 debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T15:16:49.667Z and has not been modified since then. The vulnerability affects ArcSearch for iOS versions prior to 1.48.0, allowing attacker-controlled content to imitate browser interface elements and increasing spoofing risk. Defenders should verify versions and assess exposure to potential spoofing ris [truncated]

HIGH The Browser Company of New York` CVE published 2026-06-17

CVE-2026-12348

CVE-2026-12348 is a high-severity vulnerability in Arc Search for Android that allows remote attackers to display a trusted domain in the address bar while rendering attacker-controlled content, enabling phishing. This address bar spoofing vulnerability has a CVSS score of 7.4 and was published on June 17, 2026. The vulnerability is considered high severity and could be used for phishing attacks. Users of [truncated]