logo

Arc browser launches bug bounty program after fixing RCE bug

ID: 271f10ac-66b7-5e8c-a0fa-bb52c352af80

STIX ID: report--271f10ac-66b7-5e8c-a0fa-bb52c352af80

Feed Name: Bleeping Computer

Threat Score
55/100

Date Published: 2024-10-01

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

The Browser Company disclosed and promptly patched a critical remote-code-execution flaw (CVE-2024-45489) in Arc Browser's "Boosts" customization feature that could let attackers run arbitrary JavaScript in other users' browsers by altering Boost creator IDs; the issue was responsibly reported, fixed on August 26, 2024, and Arc deployed mitigations (disabling auto-syncing of Boosts, adding toggles, releasing Arc 1.61.2) while launching a bug bounty program and external audits.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.