Arc before 1.26.1 on Windows has a bypass issue in the site settings that allows websites (with previously granted permissions) to add new permissions when the user clicks anywhere on the website.
References
Configurations
No configuration.
History
27 Jun 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-284 | |
Summary |
|
26 Jun 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-06-26 17:15
Updated : 2025-06-27 14:15
NVD link : CVE-2024-52928
Mitre link : CVE-2024-52928
CVE.ORG link : CVE-2024-52928
JSON object : View
Products Affected
No product.
CWE
CWE-284
Improper Access Control