The Browser Company

    Dashboard / Vendors

    Products: 2
    Vulnerabilities: 5
    Known Exploited: 0
    1
    Critical Level Threats
    4
    High Level Threats
    0
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-15032

    CVE-2025-15032: Increased Spoofing risk; custom new window missing about:blank

    Last Modified: Apr 15, 2026
    Published: Jan 16, 2026

    CVE-2025-14809

    Address bar spoofing risk in ArcSearch on Android

    Last Modified: Apr 15, 2026
    Published: Dec 19, 2025

    CVE-2025-14812

    Address bar spoofing risk in Arc Search on iOS

    Last Modified: Apr 15, 2026
    Published: Dec 19, 2025

    CVE-2025-13132

    Dia: Increased Spoof Risk; Missing full screen toast

    Last Modified: Apr 15, 2026
    Published: Nov 21, 2025

    CVE-2024-45489

    Arc before 2024-08-26 allows remote code execution in JavaScript boosts. Boosts that run JavaScript cannot be shared by default; however (because of misconfigured Firebase ACLs), it is possible to create or update a boost using another user's ID. This installs the boost in the victim's browser and runs arbitrary Javascript on that browser in a privileged context. NOTE: this is a no-action cloud vulnerability with zero affected users.

    Last Modified: Apr 15, 2026
    Published: Sep 20, 2024
    Items Per Page
    The_Browser_Company Vulnerabilities & Security CVEs | CVE-DB