← back
CVE-2026-94181highCWE-451

Address Bar Spoof Risk; Missing Fullscreen Notification via Select Element

18Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.4
exploitation probability
observed exploitation
nono source reports it
An address bar spoofing issue in affected versions of Arc could allow an attacker to spoof the browser address bar via a <select> element that triggers requestFullscreen without displaying the fullscreen notification.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N