CVE-2026-18534CWE-1021

CVE-2026-18534

High · published August 18, 2026

CVSS v3.1
7.4
EPSS
0%
Percentile
23.5
In the wild
Unconfirmed
What it is

ArcSearch for iOS versions prior to 1.48.0 could keep the address bar hidden after a page-initiated scroll, allowing attacker-controlled content to imitate browser interface elements and increasing spoofing risk.

The record
Technical detail
CVSS v3.1
7.4 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N
CVSS v4.0
Not supplied
EPSS
0.00311 · 23.5th percentile
Weakness
CWE-1021 · Improper Restriction of Rendered UI Layers or Frames
Published
2026-08-18T19:16Z
References (1)
EPSS history
Timeline
  • 18 AUG 14:57Z
    Address bar spoofing risk in affected iOS versions of Arc Search
    cvelistv5