The DuckDuckGo Privacy Browser application 5.26.0 for Android allows address bar spoofing via a setInterval call. The actual magic happens at `fakefunction()` above-crafted javascript file loads the real www.duckduckgo.com in a loop of every 50 ms whereas the inner HTML can be modified accordingly. The issue was closed without a fix which says team doesnt view it as a serious issue and report was marked as informative. Further CVE-2019-12329 was assigned to this issue.”]
Source: https://securityaffairs.co/wordpress/86250/hacking/duckduckgo-address-bar-spoofing.html

