com.duckduckgo.mobile.android - Cache corruption

Disclosed: 2021-09-26 23:08:52 By webklex To duckduckgo
Medium
Vulnerability Details
## Summary: By opening a special url, the app cache can be corrupted which can't be resolved by the user without reinstalling the app. ## Steps To Reproduce: 1.) Download and install the DuckDuckGo App 2.) Open `https://%22t.dev/` 3.) Try to reopen the app (The app keeps crashing) ## Additional information - Tested on Android 8.1 and 9 with the latest app release (5.73.0) - Problematic seems to be the encoded `"` (%22) ## Mitigation - Store the url urlencoded ## Impact An attacker can corrupt someones app cache and prevent the user from continuing using the app.
Actions
View on HackerOne
Report Stats
  • Report ID: 1074613
  • State: Closed
  • Substate: resolved
  • Upvotes: 12
Share this report