{"id":"CVE-2021-44683","details":"The DuckDuckGo browser 7.64.4 on iOS allows Address Bar Spoofing due to mishandling of the JavaScript window.open function (used to open a secondary browser window). This could be exploited by tricking users into supplying sensitive information such as credentials, because the address bar would display a legitimate URL, but content would be hosted on the attacker's web site.","modified":"2026-07-09T00:38:15.185745Z","published":"2022-03-25T22:15:08.033Z","references":[{"type":"EVIDENCE","url":"https://www.cybercitadel.com/remote-address-bar-spoofing-and-html-injection-disclosures/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/duckduckgo/ios","events":[{"introduced":"0"},{"fixed":"9b54e748dd1db3aa1bec50d318b0856f8eda2eb4"}],"database_specific":{"cpe":"cpe:2.3:a:duckduckgo:duckduckgo:*:*:*:*:*:iphone_os:*:*","extracted_events":[{"introduced":"0"},{"fixed":"7.64.18"}],"source":"CPE_RANGE"}}],"versions":["7.64.17","7.64.16","7.64.15","7.64.9","7.61.13","7.61.11","7.6.11","7.61.5","7.60.0","7.57.2","7.39.1.0","7.39.0.1","7.38.0","7.37.0","7.36.0.0","7.35.0.0","7.34.0.0","7.33.1.0","7.33.0.0","7.32.1.0","7.32.0.0","7.31.1.0","7.31.0.0","7.30.0.0","7.29.0.0","7.28.0.0","7.27.0.0","7.26.0.0","7.25.0.0","7.24.2.0","7.24.1","7.24.0.0","7.23.0.0","7.22.0.0","7.21.1.0","7.21.0.0","7.20.0.0","7.19.1","7.19.0.0","7.3.0.2","7.3.0.1","7.3.0.0","7.2.0.2","7.2.0.1","7.2.0.0","7.1.0.2","7.1.0.1","7.1.0.0","7.1.0","7.0.5.896","7.0.4.895","7.0.3.894","7.0.2.893","7.0.1.893","7.0.0.893","7.0.0.892","7.0.0.891","7.0.0.890","7.0.0.889","7.0.0.888","7.0.0.887","7.0.0.886","7.0.0.885","7.0.0.882","7.0.0.881","7.0.0.880","0.30.0","0.29.0","0.28.1","0.28.0","0.27.0","0.26.0","0.25.0","0.24.0","0.23.0","0.22.2","0.22.1","0.22.0","0.21.0","0.20.0","0.19.0","0.18.0","0.17.0","0.16.0","0.15.0","0.14.1","0.14.0","0.13.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-44683.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N"}]}