{"api_version":"1","generated_at":"2026-07-23T14:33:14+00:00","cve":"CVE-2020-15502","urls":{"html":"https://cve.report/CVE-2020-15502","api":"https://cve.report/api/cve/CVE-2020-15502.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-15502","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-15502"},"summary":{"title":"CVE-2020-15502","description":"** DISPUTED ** The DuckDuckGo application through 5.58.0 for Android, and through 7.47.1.0 for iOS, sends hostnames of visited web sites within HTTPS .ico requests to servers in the duckduckgo.com domain, which might make visit data available temporarily at a Potentially Unwanted Endpoint. NOTE: the vendor has stated \"the favicon service adheres to our strict privacy policy.\"","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2020-07-02 11:15:00","updated_at":"2023-11-07 03:17:00"},"problem_types":["CWE-200"],"metrics":[],"references":[{"url":"https://github.com/duckduckgo/Android/blob/e2f2d54a6b4452277467db403a3546512401b493/app/src/main/java/com/duckduckgo/app/global/UriExtension.kt#L83-L88","name":"https://github.com/duckduckgo/Android/blob/e2f2d54a6b4452277467db403a3546512401b493/app/src/main/java/com/duckduckgo/app/global/UriExtension.kt#L83-L88","refsource":"MISC","tags":["Patch","Third Party Advisory"],"title":"Android/UriExtension.kt at e2f2d54a6b4452277467db403a3546512401b493 · duckduckgo/Android · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://news.ycombinator.com/item?id=23711597","name":"https://news.ycombinator.com/item?id=23711597","refsource":"MISC","tags":["Third Party Advisory"],"title":"Hi all, Founder and CEO of DuckDuckGo here. I’m literally just waking up and rea... | Hacker News","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://news.ycombinator.com/item?id=23708166","name":"https://news.ycombinator.com/item?id=23708166","refsource":"MISC","tags":["Patch","Third Party Advisory"],"title":"DuckDuckGo browser seemingly sends domains a user visits to DDG servers | Hacker News","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/duckduckgo/Android/issues/527","name":"https://github.com/duckduckgo/Android/issues/527","refsource":"MISC","tags":["Third Party Advisory"],"title":"Domains visited get leaked to DDG servers · Issue #527 · duckduckgo/Android · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/duckduckgo/iOS/blob/1ae03d7221180bd6791cf6f7f06922a96335cf75/Core/AppUrls.swift#L98-L100","name":"https://github.com/duckduckgo/iOS/blob/1ae03d7221180bd6791cf6f7f06922a96335cf75/Core/AppUrls.swift#L98-L100","refsource":"MISC","tags":["Third Party Advisory"],"title":"iOS/AppUrls.swift at 1ae03d7221180bd6791cf6f7f06922a96335cf75 · duckduckgo/iOS · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-15502","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-15502","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"15502","vulnerable":"1","versionEndIncluding":"5.58.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"duckduckgo","cpe5":"duckduckgo","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"android","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"15502","vulnerable":"1","versionEndIncluding":"7.47.1.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"duckduckgo","cpe5":"duckduckgo","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"iphone_os","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2020-15502","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"** DISPUTED ** The DuckDuckGo application through 5.58.0 for Android, and through 7.47.1.0 for iOS, sends hostnames of visited web sites within HTTPS .ico requests to servers in the duckduckgo.com domain, which might make visit data available temporarily at a Potentially Unwanted Endpoint. NOTE: the vendor has stated \"the favicon service adheres to our strict privacy policy.\""}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://github.com/duckduckgo/Android/blob/e2f2d54a6b4452277467db403a3546512401b493/app/src/main/java/com/duckduckgo/app/global/UriExtension.kt#L83-L88","refsource":"MISC","name":"https://github.com/duckduckgo/Android/blob/e2f2d54a6b4452277467db403a3546512401b493/app/src/main/java/com/duckduckgo/app/global/UriExtension.kt#L83-L88"},{"url":"https://github.com/duckduckgo/iOS/blob/1ae03d7221180bd6791cf6f7f06922a96335cf75/Core/AppUrls.swift#L98-L100","refsource":"MISC","name":"https://github.com/duckduckgo/iOS/blob/1ae03d7221180bd6791cf6f7f06922a96335cf75/Core/AppUrls.swift#L98-L100"},{"url":"https://news.ycombinator.com/item?id=23708166","refsource":"MISC","name":"https://news.ycombinator.com/item?id=23708166"},{"url":"https://github.com/duckduckgo/Android/issues/527","refsource":"MISC","name":"https://github.com/duckduckgo/Android/issues/527"},{"url":"https://news.ycombinator.com/item?id=23711597","refsource":"MISC","name":"https://news.ycombinator.com/item?id=23711597"}]}},"nvd":{"publishedDate":"2020-07-02 11:15:00","lastModifiedDate":"2023-11-07 03:17:00","problem_types":["CWE-200"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:duckduckgo:duckduckgo:*:*:*:*:*:iphone_os:*:*","versionEndIncluding":"7.47.1.0","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:duckduckgo:duckduckgo:*:*:*:*:*:android:*:*","versionEndIncluding":"5.58.0","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"15502","Ordinal":"176887","Title":"CVE-2020-15502","CVE":"CVE-2020-15502","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"15502","Ordinal":"1","NoteData":"** DISPUTED ** The DuckDuckGo application through 5.58.0 for Android, and through 7.47.1.0 for iOS, sends hostnames of visited web sites within HTTPS .ico requests to servers in the duckduckgo.com domain, which might make visit data available temporarily at a Potentially Unwanted Endpoint. NOTE: the vendor has stated \"the favicon service adheres to our strict privacy policy.\"","Type":"Description","Title":null},{"CveYear":"2020","CveId":"15502","Ordinal":"2","NoteData":"2020-07-02","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"15502","Ordinal":"3","NoteData":"2020-07-02","Type":"Other","Title":"Modified"}]}}}