Arc before 1.26.1 on Windows has a bypass issue in the site settings that allows websites (with previously granted permissions) to add new permissions when the user clicks anywhere on the website.
History

Thu, 10 Jul 2025 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft
Microsoft windows
Thebrowser
Thebrowser arc
CPEs cpe:2.3:a:thebrowser:arc:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows
Thebrowser
Thebrowser arc

Fri, 27 Jun 2025 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 26 Jun 2025 17:15:00 +0000

Type Values Removed Values Added
Description Arc before 1.26.1 on Windows has a bypass issue in the site settings that allows websites (with previously granted permissions) to add new permissions when the user clicks anywhere on the website.
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AC:L/AV:N/A:L/C:H/I:H/PR:N/S:C/UI:R'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-06-27T13:38:43.810Z

Reserved: 2024-11-18T00:00:00.000Z

Link: CVE-2024-52928

cve-icon Vulnrichment

Updated: 2025-06-27T13:38:32.346Z

cve-icon NVD

Status : Analyzed

Published: 2025-06-26T17:15:30.287

Modified: 2025-07-10T00:59:09.070

Link: CVE-2024-52928

cve-icon Redhat

No data.