Back to search
CVE-2020-15502
Published: Jul 2, 2020
Modified: Aug 4, 2024
PUBLISHED
Description
The DuckDuckGo application through 5.58.0 for Android, and through 7.47.1.0 for iOS, sends hostnames of visited web sites within HTTPS .ico requests to servers in the duckduckgo.com domain, which might make visit data available temporarily at a Potentially Unwanted Endpoint. NOTE: the vendor has stated "the favicon service adheres to our strict privacy policy.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://news.ycombinator.com/item?id=23708166
x_refsource_MISC
https://github.com/duckduckgo/Android/issues/527
x_refsource_MISC
https://news.ycombinator.com/item?id=23711597
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now