SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-18534

HIGH · CVSS 7.4 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-08-18 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

ArcSearch for iOS versions prior to 1.48.0 is vulnerable to a spoofing attack due to the address bar remaining hidden after a page-initiated scroll, enabling malicious content to mimic legitimate browser interface elements. This could lead to users being misled into interacting with fraudulent sites or content. Developers and security teams managing iOS applications should prioritize this vulnerability to mitigate potential risks to user trust and data security.

CVE
CVE-2026-18534
Severity
HIGH
CVSS
7.4
EPSS
0.31%

Original NVD Description

ArcSearch for iOS versions prior to 1.48.0 could keep the address bar hidden after a page-initiated scroll, allowing attacker-controlled content to imitate browser interface elements and increasing spoofing risk.