Skip to content
DuckDuckGo Browser UXSS Flaw in Auto Consent JS Bridge Enables Cross

DuckDuckGo Browser UXSS Flaw in Auto Consent JS Bridge Enables Cross

Cybersecuritynews •Abinaya • March 2, 2026

A critical Universal Cross-Site Scripting (UXSS) vulnerability was recently discovered in the DuckDuckGo Android browser. This flaw allowed untrusted, cross-origin iframes to execute arbitrary JavaScript in the top-level origin, tracked with a high-severity CVSS score of 8.6. The vulnerability was originally detailed in a Medium post by security researcher Dhiraj Mishra. The vulnerability stems from […]

Extracted Entities

MITRE ATT&CK (1)

Platforms (1)

Vulnerabilities (2)