ArcSearch for Android versions prior to 1.12.6 could display a different domain in the address bar than the content being shown, enabling address bar spoofing after user interaction via crafted web content.
References
Configurations
No configuration.
History
19 Dec 2025, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-19 17:15
Updated : 2025-12-19 18:00
NVD link : CVE-2025-14809
Mitre link : CVE-2025-14809
CVE.ORG link : CVE-2025-14809
JSON object : View
Products Affected
No product.
CWE
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
