VYPR

Chromecast Firmware

by Google

CVEs (6)

  • CVE-2023-48426CriApr 5, 2024
    risk 0.65cvss 10.0epss 0.00

    u-boot bug that allows for u-boot shell and interrupt over UART

  • CVE-2023-6181CriDec 11, 2023
    risk 0.64cvss 9.8epss 0.00

    An oversight in BCB handling of reboot reason that allows for persistent code execution

  • CVE-2023-48425CriDec 11, 2023
    risk 0.64cvss 9.8epss 0.00

    U-Boot vulnerability resulting in persistent Code Execution 

  • CVE-2023-48424CriDec 11, 2023
    risk 0.64cvss 9.8epss 0.00

    U-Boot shell vulnerability resulting in Privilege escalation in a production device

  • CVE-2023-48417CriDec 11, 2023
    risk 0.64cvss 9.8epss 0.00

    Missing Permission checks resulting in unauthorized access and Manipulation in KeyChainActivity Application

  • CVE-2018-12716MedJun 25, 2018
    risk 0.28cvss 4.3epss 0.01

    The API service on Google Home and Chromecast devices before mid-July 2018 does not prevent DNS rebinding attacks from reading the scan_results JSON data, which allows remote attackers to determine the physical location of most web browsers by leveraging the presence of one of…