Description


ArcSearch for iOS versions prior to 1.45.2 could display a different domain in the address bar than the content being shown after an iframe-triggered URI-scheme navigation, increasing spoofing risk.

Related CPE's


Could not find any relations

Weaknesses



CWE-1021

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

7.5 · High

  • CVSS V3.1

  • CVSS V3.0

  • CVSS V2.0

Information


Source identifier

59469e6c-7ea7-446f-8e43-06aa32c115e8

Vulnerability status

Awaiting analysis

Published

2025-12-19T17:15:50.957

3 hours ago

Last modified

2025-12-19T18:00:18.330

3 hours ago