UXSS Vulnerability in DuckDuckGo Browser’s AutoConsent JS Bridge Allows Cross-Origin Attacks
ID: 90606e0b-5714-589d-862c-78afb7e5680a
STIX ID: report--90606e0b-5714-589d-862c-78afb7e5680a
Feed Name: GBHackers
Threat Score
A critical UXSS vulnerability was found in DuckDuckGo Android's AutoConsent JS bridge, allowing cross-origin iframes to cause the browser to execute arbitrary JavaScript in the top-level page (PoC demonstrated altering page text). The flaw (CVSS 8.6) was reported via HackerOne and has been patched; users should update to the latest DuckDuckGo app to mitigate risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
