CVE-2025-48464: Duckduckgo Browser

Medium severity, CVSS 4.7. EPSS: 0.1% chance of exploitation in the next 30 days.

Successful exploitation of the vulnerability could allow an unauthenticated attacker to gain access to a victim’s Sync account data such as account credentials and email protection information.

Affected products

  • Duckduckgo Duckduckgo Browser: up to and including 5.246.0

Published 2025-10-08. Last modified 2026-10-08.