DuckDuckGo's vulnerability profile centers on its privacy-focused search engine and related browser extensions, with observed weaknesses clustering around information-disclosure issues and improper UI-layer isolation. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Duckduckgo over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-6849MEDIUM In the WebRTC component in DuckDuckGo 4.2.0, after visiting a web site that attempts to gather complete client information (such as https://ip.voidsec.com), the browser can disclos | Apr 1, 2018 | 4.3 | 51 | NO | YES |
CVE-2021-44683HIGH The DuckDuckGo browser 7.64.4 on iOS allows Address Bar Spoofing due to mishandling of the JavaScript window.open function (used to open a secondary browser window). This could be | Mar 25, 2022 | 8.2 | 25 | NO | NO |
CVE-2020-15502HIGH The DuckDuckGo application through 5.58.0 for Android, and through 7.47.1.0 for iOS, sends hostnames of visited web sites within HTTPS .ico requests to servers in the duckduckgo.co | Jul 2, 2020 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Duckduckgo.
Media articles that mention a CVE ID that affects a product developed by Duckduckgo — matched by CVE ID, not by vendor name.