Unauthenticated Access Vulnerability in Sync by Affected Vendor
CVE-2025-48464

4.7MEDIUM

Key Information:

Vendor

Duckduckgo

Vendor
CVE Published:
8 October 2025

What is CVE-2025-48464?

An unauthenticated access vulnerability in Sync enables attackers to exploit the system without the need for authentication, potentially allowing them to retrieve sensitive account information. Successful exploitation can lead to unauthorized access to user data, including account credentials and protected email information, thereby posing a serious risk to user security and privacy. Users of Sync are advised to apply necessary patches and maintain updated software to mitigate this threat.

Affected Version(s)

DuckDuckGo Browser 5.246.0 and below

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Leng Kang Hao
.
CVE-2025-48464 : Unauthenticated Access Vulnerability in Sync by Affected Vendor