The Browser Company of New York
First CVE: Nov 21, 2025Active for: 1 year
6
CVEs Published
More CVEs Published than 18% of tracked CNAs
3.0
Avg CVEs / Year
More Avg CVEs / Year than 19% of tracked CNAs
7.3
Avg CVSS Score
Higher Avg CVSS Score than 57% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by The Browser Company of New York over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 21, 2025
8 months ago
Most Recent CVE
Jun 16, 2026
38 days ago
Top CVEs
All CVEs published by The Browser Company of New York as a CNA, regardless of affected vendor or product.
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-12348HIGH Address bar spoofing in Arc Search for Android allows a remote attacker to display a trusted domain in the address bar while rendering attacker-controlled content, enabling phishin | Jun 16, 2026 | 7.4 | 30 | NO | NO |
CVE-2025-15032HIGH Missing about:blank indicator in custom-sized new windows in Dia before 1.9.0 on macOS could allow an attacker to spoof a trusted domain in the window title and mislead users about | Jan 16, 2026 | 7.4 | 24 | NO | NO |
CVE-2025-14812HIGH ArcSearch for iOS versions prior to 1.45.2 could display a different domain in the address bar than the content being shown after an iframe-triggered URI-scheme navigation, increas | Dec 19, 2025 | 7.5 | 24 | NO | NO |
CVE-2025-13132HIGH This vulnerability allowed a site to enter fullscreen, after a user click, without a full-screen notification (toast) appearing. Without this notification, users could potentially | Nov 21, 2025 | 7.4 | 24 | NO | NO |
CVE-2025-14809HIGH ArcSearch for Android versions prior to 1.12.6 could display a different domain in the address bar than the content being shown, enabling address bar spoofing after user interactio | Dec 19, 2025 | 7.4 | 23 | NO | NO |
CVE-2026-2378MEDIUM ArcSearch for Android versions prior to 1.12.7 could display a different domain in the address bar than the content being shown, enabling address bar spoofing after user interactio | Mar 20, 2026 | 6.5 | 22 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA6 CVEs
17%
83%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network6 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None1 (16.7%)
Unknown0 (0.0%)
Required5 (83.3%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None6 (100.0%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (6 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by The Browser Company of New York as a CNA.
Media Mentions
Media articles that mention a CVE ID published by The Browser Company of New York as a CNA — matched by CVE ID, not by organization name.