← Back

Chromecast Firmware

chromecast_firmware

Vendor: Google • 6 CVEs

CVEs (6)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
1Chromecast Firmware
Jun 17, 2026
Apr 5, 2024
N/A· v4
10.0 CRITICAL· v3
N/A· v2
u-boot bug that allows for u-boot shell and interrupt over UART
1Google
1Chromecast Firmware
Jun 17, 2026
Dec 11, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An oversight in BCB handling of reboot reason that allows for persistent code execution
1Google
1Chromecast Firmware
Jun 17, 2026
Dec 11, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
U-Boot vulnerability resulting in persistent Code Execution 
1Google
1Chromecast Firmware
Jun 17, 2026
Dec 11, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
U-Boot shell vulnerability resulting in Privilege escalation in a production device
1Google
1Chromecast Firmware
Jun 17, 2026
Dec 11, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Missing Permission checks resulting in unauthorized access and Manipulation in KeyChainActivity Application
1Google
2Chromecast Firmware
Home Firmware
Nov 21, 2024
Jun 25, 2018
N/A· v4
4.3 MEDIUM· v3
3.3 LOW· v2
The API service on Google Home and Chromecast devices before mid-July 2018 does not prevent DNS rebinding attacks from reading the scan_results JSON data, which allows remote attackers to determine the physical location...Show more
The API service on Google Home and Chromecast devices before mid-July 2018 does not prevent DNS rebinding attacks from reading the scan_results JSON data, which allows remote attackers to determine the physical location of most web browsers by leveraging the presence of one of these devices on its local network, extracting the scan_results bssid fields, and sending these fields in a geolocation/v1/geolocate Google Maps Geolocation API request.Show less