Arc before 1.26.1 on Windows has a bypass issue in the site settings that allows websites (with previously granted permissions) to add new permissions when the user clicks anywhere on the website.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
https://thebrowser.company | product |
https://arc.net/security/bulletins#windows-site-settings-bypass-cve-2024-52928 | vendor advisory |