The DuckDuckGo application through 5.58.0 for Android, and through 7.47.1.0 for iOS, sends hostnames of visited web sites within HTTPS .ico requests to servers in the duckduckgo.com domain, which might make visit data available temporarily at a Potentially Unwanted Endpoint. NOTE: the vendor has stated "the favicon service adheres to our strict privacy policy.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2020-07-02T10:59:20

Updated: 2024-06-26T19:55:36.602Z

Reserved: 2020-07-02T00:00:00


Link: CVE-2020-15502

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2020-07-02T11:15:10.823

Modified: 2024-06-26T20:15:13.700


Link: CVE-2020-15502

JSON object: View

cve-icon Redhat Information

No data.

CWE