logo

DuckDuckGo Browser UXSS Flaw in Auto Consent JS Bridge Enables Cross-Origin Code Execution

ID: 18d66ee5-ebe8-5fe1-a79d-71eb5772f396

STIX ID: report--18d66ee5-ebe8-5fe1-a79d-71eb5772f396

Feed Name: cybersecurityNews.com

Threat Score
72/100

Date Published: 2026-03-02

Date Updated: 2026-04-21

Author: Abinaya

...
...

The report describes a critical UXSS vulnerability (CVSS 8.6) in the DuckDuckGo Android browser's AutoconsentAndroid JS bridge that accepted messages from any frame and used webView.evaluateJavascript(...) to run code in the top-level page, allowing cross-origin iframes to execute arbitrary JavaScript; the issue was responsibly disclosed via HackerOne and has been patched, and users should update the app to mitigate risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.