Vulnerability · NVD
CVE-2020-15502
HIGH 7.5
The DuckDuckGo application through 5.58.0 for Android, and through 7.47.1.0 for iOS, sends hostnames of visited web sites within HTTPS .ico requests to servers in the duckduckgo.com domain, which might make visit data available temporarily at a Potentially Unwanted Endpoint. NOTE: the vendor has stated "the favicon service adheres to our strict privacy policy.
Attack vector : Network
No privileges required
No user interaction
Show raw CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
1.53%
above median
percentile 72.4%
Tracked apps referencing this CVE
For each app: the affected range, the fixing version, and where the tracked app stands today.
Vulnerable CPE configurations (2)
| Vendor | Product | Platform | Versions | CPE 2.3 URI |
|---|---|---|---|---|
| duckduckgo |
duckduckgo Android
|
Android | ≤5.58.0 | cpe:2.3:a:duckduckgo:duckduckgo:*:*:*:*:*:android:*:* |
| duckduckgo |
duckduckgo iOS
|
iOS | ≤7.47.1.0 | cpe:2.3:a:duckduckgo:duckduckgo:*:*:*:*:*:iphone_os:*:* |