WebRTC Private IP Disclosure in DuckDuckGo Browser
CVE-2018-6849

4.3MEDIUM

Key Information:

Vendor

Duckduckgo

Vendor
CVE Published:
1 April 2018

What is CVE-2018-6849?

In version 4.2.0 of the DuckDuckGo browser, a vulnerability in the WebRTC component allows the disclosure of the user's private IP address. When visiting specific websites designed to exploit this flaw, such as https://ip.voidsec.com, the browser inadvertently sends a STUN request that includes the private IP address of the client. This poses a potential risk to user privacy, as sensitive network information may be exposed, enabling tracking or other malicious activities. Users of DuckDuckGo are encouraged to take precautions to mitigate the risk of this information being leaked.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

EPSS Score

76% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.