Arc team patched it. The vulnerability was on the firebase side it seems. Josh (CEO of the browser company) updated the twitter thread with this https://x.com/joshm/status/1838594111621755251?s=46