VYPR

Chromecast

by Google

CVEs (15)

  • CVE-2023-48426CriApr 5, 2024
    risk 0.65cvss 10.0epss 0.00

    u-boot bug that allows for u-boot shell and interrupt over UART

  • CVE-2023-6181CriDec 11, 2023
    risk 0.64cvss 9.8epss 0.00

    An oversight in BCB handling of reboot reason that allows for persistent code execution

  • CVE-2022-42541CriNov 29, 2023
    risk 0.64cvss 9.8epss 0.01

    Remote code execution

  • CVE-2022-42537CriNov 29, 2023
    risk 0.64cvss 9.8epss 0.00

    Remote code execution

  • CVE-2022-42536CriNov 29, 2023
    risk 0.64cvss 9.8epss 0.00

    Remote code execution

  • CVE-2026-78939CriAug 25, 2026
    risk 0.62cvss 9.6epss 0.00

    Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-17672CriJul 30, 2026
    risk 0.62cvss 9.6epss 0.00

    Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-16416CriJul 21, 2026
    risk 0.60cvss 9.3epss 0.00

    Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: High)

  • CVE-2026-79224HigAug 25, 2026
    risk 0.54cvss 8.3epss 0.00

    Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2026-79121HigAug 25, 2026
    risk 0.54cvss 8.3epss 0.00

    Improper input validation in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2026-79054HigAug 25, 2026
    risk 0.54cvss 8.3epss 0.00

    Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2026-10924HigJun 4, 2026
    risk 0.54cvss 8.3epss 0.00

    Integer overflow in Chromecast in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-16414HigJul 21, 2026
    risk 0.51cvss 7.8epss 0.00

    Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: High)

  • CVE-2026-14048MedJun 30, 2026
    risk 0.42cvss 6.5epss 0.00

    Use after free in Chromecast in Google Chrome prior to 150.0.7871.47 allowed an attacker on the local network segment to obtain potentially sensitive information from process memory via a malicious peripheral. (Chromium security severity: Low)

  • CVE-2018-12716MedJun 25, 2018
    risk 0.28cvss 4.3epss 0.01

    The API service on Google Home and Chromecast devices before mid-July 2018 does not prevent DNS rebinding attacks from reading the scan_results JSON data, which allows remote attackers to determine the physical location of most web browsers by leveraging the presence of one of…