VYPR

Chromecast

by Google

CVEs (8)

  • CVE-2023-48426CriApr 5, 2024
    risk 0.65cvss 10.0epss 0.00

    u-boot bug that allows for u-boot shell and interrupt over UART

  • CVE-2023-6181CriDec 11, 2023
    risk 0.64cvss 9.8epss 0.00

    An oversight in BCB handling of reboot reason that allows for persistent code execution

  • CVE-2022-42541CriNov 29, 2023
    risk 0.64cvss 9.8epss 0.01

    Remote code execution

  • CVE-2022-42537CriNov 29, 2023
    risk 0.64cvss 9.8epss 0.00

    Remote code execution

  • CVE-2022-42536CriNov 29, 2023
    risk 0.64cvss 9.8epss 0.00

    Remote code execution

  • CVE-2026-10884HigJun 4, 2026
    risk 0.54cvss 8.3epss 0.00

    Use after free in Chromecast in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2026-9123HigMay 20, 2026
    risk 0.49cvss 7.5epss 0.00

    Heap buffer overflow in Chromecast in Google Chrome on Android, Linux, ChromeOS prior to 148.0.7778.179 allowed a local attacker to execute arbitrary code inside a sandbox via malicious network traffic. (Chromium security severity: Medium)

  • CVE-2018-12716MedJun 25, 2018
    risk 0.28cvss 4.3epss 0.01

    The API service on Google Home and Chromecast devices before mid-July 2018 does not prevent DNS rebinding attacks from reading the scan_results JSON data, which allows remote attackers to determine the physical location of most web browsers by leveraging the presence of one of…