← Back

Home Firmware

home_firmware

Vendor: Google • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
4Home Firmware
Home Mini FirmwareNest Audio Firmware+1 more
Jun 17, 2026
Jan 2, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An attacker in the wifi vicinity of a target Google Home can spy on the victim, resulting in Elevation of Privilege 
1Google
2Chromecast Firmware
Home Firmware
Nov 21, 2024
Jun 25, 2018
N/A· v4
4.3 MEDIUM· v3
3.3 LOW· v2
The API service on Google Home and Chromecast devices before mid-July 2018 does not prevent DNS rebinding attacks from reading the scan_results JSON data, which allows remote attackers to determine the physical location...Show more
The API service on Google Home and Chromecast devices before mid-July 2018 does not prevent DNS rebinding attacks from reading the scan_results JSON data, which allows remote attackers to determine the physical location of most web browsers by leveraging the presence of one of these devices on its local network, extracting the scan_results bssid fields, and sending these fields in a geolocation/v1/geolocate Google Maps Geolocation API request.Show less