CVE-2024-52928

Severity CVSS v4.0:
Pending analysis
Type:
CWE-284 Improper Access Control
Publication date:
26/06/2025
Last modified:
10/07/2025

Description

Arc before 1.26.1 on Windows has a bypass issue in the site settings that allows websites (with previously granted permissions) to add new permissions when the user clicks anywhere on the website.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:thebrowser:arc:*:*:*:*:*:*:*:* 1.26.1 (excluding)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*