Thebrowser's vulnerability footprint concentrates around its Arc browser and Arc Search products, with the durable signal centered on access-control and UI-layer rendering issues that characterize browser-based applications. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Thebrowser over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-2378MEDIUM ArcSearch for Android versions prior to 1.12.7 could display a different domain in the address bar than the content being shown, enabling address bar spoofing after user interactio | Mar 20, 2026 | 6.5 | 22 | NO | NO |
CVE-2024-52928HIGH Arc before 1.26.1 on Windows has a bypass issue in the site settings that allows websites (with previously granted permissions) to add new permissions when the user clicks anywhere | Jun 26, 2025 | 8.3 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Thebrowser.
Media articles that mention a CVE ID that affects a product developed by Thebrowser — matched by CVE ID, not by vendor name.