What is CVE-2026-18534?
CVE-2026-18534 affects ArcSearch for iOS versions prior to 1.48.0, where the address bar could remain hidden after a page-initiated scroll. This allows attacker-controlled content to mimic browser UI elements, increasing the risk of spoofing attacks. Users should update to version 1.48.0 or later immediately.
Azərbaycanca: CVE-2026-18534, iOS üçün ArcSearch brauzerinin 1.48.0-dan əvvəlki versiyalarında aşkarlanıb. Zəiflik səhifənin sürüşdürülməsi zamanı ünvan sətrinin gizli qalmasına səbəb olur ki, bu da təcavüzkara brauzer interfeysini təqlid etməyə və fişinq riskini artırmağa imkan verir. İstifadəçilər dərhal 1.48.0 və ya daha yeni versiyaya yeniləməlidir.
FAQ2
Which browser is affected by CVE-2026-18534 and what causes the main phishing risk?
The vulnerability affects ArcSearch for iOS versions prior to 1.48.0. The risk arises because the address bar can remain hidden after a page-initiated scroll, allowing attackers to mimic browser UI elements.
To which version should users update to protect against CVE-2026-18534?
Users should immediately update the ArcSearch browser to version 1.48.0 or later to protect against this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.