News

In Android version of DuckDuckGo browser found vulnerability that helps faking URL

Independent researcher Dhiraj Mishra discovered a vulnerability in Android version of DuckDuckGo browser (version 5.26.0) that was downloaded and installed more than 5 000 000 times.

Bug received identified CVE-2019-12329 and allows substituting URL in the address line of the protected browser, cheating the user.

The problem is that content of the address line can be faked.

“It was observed that the DuckDuckGo privacy browser ominibar can be spoofed by a crafted javascript page spoofing setInterval` function and reloading the URL in every 10 to 50 ms.”, — reported Dhiraj Mishra.

While real website duckduckgo.com automatically loads every 50 milliseconds, researcher managed to have reflection of the entirely different content in browser.

PoC-exploit can be seen below.
duckduckgo poc-exploitduckduckgo poc-exploit

Internet-security specialists have good reasons to call such attacks to be the worst type of fishing, as if user cannot trust its own browsers’ address line, the things are bad.

Issue is still not fixed, though researcher reported about it via HackerOne platform in October 2018. After a long discussion, DuckDuckGo developers preferred to mark report on vulnerability as “informative”, paid a revenue to a researcher, but said that do not view bug as a serious vulnerability.

Source: https://securityaffairs.co

Daniel Zimmermann

Daniel Zimmermann has been writing on security and malware subjects for many years and has been working in the security industry for over 10 years. Daniel was educated at the Saarland University in Saarbrücken, Germany and currently lives in New York.

Recent Posts

Remove CmbLabs Virus (.cmblabs Files Ransomware)

CmbLabs Virus - Details CmbLabs stands for a ransomware-type infection. CmbLabs was elaborated particularly to…

1 hour ago

Remove Yttnmx.co.in pop-up ads (Virus Removal Guide)

Yttnmx.co.in is a domain that tries to force you into subscribing to its browser notifications…

13 hours ago

Remove Starcat Virus (.starcat Files Ransomware)

Starcat - General Info Starcat mean a ransomware-type infection. Starcat was elaborated particularly to encrypt…

1 day ago

Remove PetyaX Virus (.petyax Files Ransomware)

PetyaX - Ransomware PetyaX stands for a ransomware-type infection. PetyaX was elaborated specifically to encrypt…

1 day ago

Remove Fripolonishnity.co.in pop-up ads (Virus Removal Guide)

Fripolonishnity.co.in is a domain that tries to force you into subscribing to its browser notifications…

1 day ago

Remove Hotbpekare.today pop-up ads (Virus Removal Guide)

Hotbpekare.today is a site that tries to force you into clik to its browser notifications…

2 days ago