Arc before 1.26.1 on Windows has a bypass issue in the site settings that allows websites (with previously granted permissions) to add new permissions when the user clicks anywhere on the website.
History

Fri, 27 Jun 2025 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 26 Jun 2025 17:15:00 +0000

Type Values Removed Values Added
Description Arc before 1.26.1 on Windows has a bypass issue in the site settings that allows websites (with previously granted permissions) to add new permissions when the user clicks anywhere on the website.
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AC:L/AV:N/A:L/C:H/I:H/PR:N/S:C/UI:R'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-06-26T00:00:00.000Z

Updated: 2025-06-27T13:38:43.810Z

Reserved: 2024-11-18T00:00:00.000Z

Link: CVE-2024-52928

cve-icon Vulnrichment

Updated: 2025-06-27T13:38:32.346Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-26T17:15:30.287

Modified: 2025-06-27T14:15:33.280

Link: CVE-2024-52928

cve-icon Redhat

No data.