Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade ArcSearch on Android to version 1.12.6 or newer
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 21 Dec 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Google
Google android The Browser Company The Browser Company arc |
|
| Vendors & Products |
Google
Google android The Browser Company The Browser Company arc |
Fri, 19 Dec 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 19 Dec 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ArcSearch for Android versions prior to 1.12.6 could display a different domain in the address bar than the content being shown, enabling address bar spoofing after user interaction via crafted web content. | |
| Title | Address bar spoofing risk in ArcSearch on Android | |
| Weaknesses | CWE-1021 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: BCNY
Published:
Updated: 2025-12-19T18:00:13.120Z
Reserved: 2025-12-16T22:49:28.363Z
Link: CVE-2025-14809
Updated: 2025-12-19T17:23:55.289Z
Status : Deferred
Published: 2025-12-19T17:15:50.800
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-14809
No data.
OpenCVE Enrichment
Updated: 2025-12-21T21:12:54Z