Press and hold to continue

This page is the attacker. It is on a different registrable domain from the target site and it never receives the target's cookie in JavaScript: that cookie is HttpOnly, Secure, SameSite=Strict and host-only.

1. Sign in to the target site, then come back.
Target: bank.teiubescdalghezamea.app
2. Press and hold anywhere on this page, then tap Download image.
That is the whole interaction. There is no permission prompt and no security dialog.
WAITING - the attacker origin has received no cookie
Zero-click probe, running by itself since this page loaded: a 1px iframe pointed at https://bank.teiubescdalghezamea.app/export.bin, a download-triggering URL on the target site. In Arc that alone produces an authenticated HEAD plus an authenticated GET and writes the victim's private response body into /sdcard/Download/. Check the raw log.