{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-94181", "assignerOrgId": "59469e6c-7ea7-446f-8e43-06aa32c115e8", "state": "PUBLISHED", "assignerShortName": "BCNY", "dateReserved": "2026-09-21T00:50:04.410Z", "datePublished": "2026-09-23T18:55:08.973Z", "dateUpdated": "2026-09-23T19:35:35.801Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "59469e6c-7ea7-446f-8e43-06aa32c115e8", "shortName": "BCNY", "dateUpdated": "2026-09-23T18:55:08.973Z" }, "title": "Address Bar Spoof Risk; Missing Fullscreen Notification via Select Element", "datePublic": "2026-09-23T18:48:00.000Z", "problemTypes": [ { "descriptions": [ { "lang": "en", "cweId": "CWE-451", "description": "CWE-451 User Interface (UI) Misrepresentation of Critical Information", "type": "CWE" } ] } ], "impacts": [ { "capecId": "CAPEC-148", "descriptions": [ { "lang": "en", "value": "CAPEC-148 Content Spoofing" } ] } ], "affected": [ { "vendor": "The Browser Company of New York", "product": "Arc", "platforms": [ "MacOS" ], "versions": [ { "status": "affected", "version": "0", "lessThan": "1.159.0", "versionType": "semver" } ], "defaultStatus": "unaffected" } ], "descriptions": [ { "lang": "en", "value": "An address bar spoofing issue in affected versions of Arc could allow an attacker to spoof the browser address bar via a