Skip to content
Appaloosa Scout

Vulnerability · NVD

CVE-2020-15502

HIGH 7.5

The DuckDuckGo application through 5.58.0 for Android, and through 7.47.1.0 for iOS, sends hostnames of visited web sites within HTTPS .ico requests to servers in the duckduckgo.com domain, which might make visit data available temporarily at a Potentially Unwanted Endpoint. NOTE: the vendor has stated "the favicon service adheres to our strict privacy policy.

Attack vector : Network No privileges required No user interaction
Show raw CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS 1.53% above median percentile 72.4%

Tracked apps referencing this CVE

For each app: the affected range, the fixing version, and where the tracked app stands today.

Vulnerable CPE configurations (2)
Vendor Product Versions
duckduckgo duckduckgo
Android
≤5.58.0
duckduckgo duckduckgo
iOS
≤7.47.1.0
View on NVD ↗ Advisory · github.com Advisory · news.ycombinator.com