DuckDuckGo Browser UXSS Flaw in Auto Consent JS Bridge Enables Cross-Origin Code Execution
ID: 18d66ee5-ebe8-5fe1-a79d-71eb5772f396
STIX ID: report--18d66ee5-ebe8-5fe1-a79d-71eb5772f396
Feed Name: cybersecurityNews.com
Threat Score
The report describes a critical UXSS vulnerability (CVSS 8.6) in the DuckDuckGo Android browser's AutoconsentAndroid JS bridge that accepted messages from any frame and used webView.evaluateJavascript(...) to run code in the top-level page, allowing cross-origin iframes to execute arbitrary JavaScript; the issue was responsibly disclosed via HackerOne and has been patched, and users should update the app to mitigate risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
