4.7
/ 10
MEDIUM
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
Description
Successful exploitation of the vulnerability could allow an unauthenticated attacker to gain access to a victim’s Sync account data such as account credentials and email protection information.
Basic Information
ID
CVE-2025-48464
Source
CSA
Published
Oct 8, 2025 at 06:50
Affected Product
Vendor
DuckDuckGo
Product
DuckDuckGo Browser
Version
5.246.0 and below
Affected Versions
DuckDuckGo DuckDuckGo Browser 5.246.0 and below