CVE-2025-14812 describes a spoofing vulnerability in ArcSearch for iOS versions prior to 1.45.2. This flaw allows the application to display a legitimate domain in the address bar while showing content from a different, potentially malicious, source after an iframe-triggered URI-scheme navigation. Rated as HIGH severity with a CVSS score of 7.5, the vulnerability is easily exploitable over the network without user interaction, leading to a high integrity impact. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| The Browser Company Of New York | ArcSearch | >= 0, < 1.45.2CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.