CVE-2026-94181: The Browser Company Of New York Arc
High severity, CVSS 7.4. EPSS: 0.3% chance of exploitation in the next 30 days.
An address bar spoofing issue in affected versions of Arc could allow an attacker to spoof the browser address bar via a <select> element that triggers requestFullscreen without displaying the fullscreen notification.
Affected products
- The Browser Company Of New York Arc: before 1.159.0 (fixed in 1.159.0)
Published 2026-09-23. Last modified 2026-09-24.