uXSS Vulnerability in DuckDuckGo Browser's AutoConsent JS Bridge Discovered

uXSS Vulnerability in DuckDuckGo Browser's AutoConsent JS Bridge Discovered

First seen 2 Mar 2026, 14:10 UTC GbhackersCyberpressCybersecuritynews 31.2

Article Content

Browse articles
ThreatCluster

A Universal Cross-Site Scripting (uXSS) vulnerability has been identified in the DuckDuckGo browser, specifically within the AutoConsent JavaScript bridge. This flaw allows attackers to exploit the bridge, potentially compromising user security. Users of the DuckDuckGo browser are affected by this vulnerability.

Timeline

2026-03-02
Vulnerability reported in DuckDuckGo browser
Recent
Patch released for the uXSS flaw