Chromecast
by Google
CVEs (15)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-48426 | Cri | 0.65 | 10.0 | 0.00 | Apr 5, 2024 | u-boot bug that allows for u-boot shell and interrupt over UART | ||
| CVE-2023-6181 | Cri | 0.64 | 9.8 | 0.00 | Dec 11, 2023 | An oversight in BCB handling of reboot reason that allows for persistent code execution | ||
| CVE-2022-42541 | Cri | 0.64 | 9.8 | 0.01 | Nov 29, 2023 | Remote code execution | ||
| CVE-2022-42537 | Cri | 0.64 | 9.8 | 0.00 | Nov 29, 2023 | Remote code execution | ||
| CVE-2022-42536 | Cri | 0.64 | 9.8 | 0.00 | Nov 29, 2023 | Remote code execution | ||
| CVE-2026-78939 | Cri | 0.62 | 9.6 | 0.00 | Aug 25, 2026 | Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2026-17672 | Cri | 0.62 | 9.6 | 0.00 | Jul 30, 2026 | Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2026-16416 | Cri | 0.60 | 9.3 | 0.00 | Jul 21, 2026 | Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: High) | ||
| CVE-2026-79224 | Hig | 0.54 | 8.3 | 0.00 | Aug 25, 2026 | Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) | ||
| CVE-2026-79121 | Hig | 0.54 | 8.3 | 0.00 | Aug 25, 2026 | Improper input validation in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) | ||
| CVE-2026-79054 | Hig | 0.54 | 8.3 | 0.00 | Aug 25, 2026 | Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) | ||
| CVE-2026-10924 | Hig | 0.54 | 8.3 | 0.00 | Jun 4, 2026 | Integer overflow in Chromecast in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2026-16414 | Hig | 0.51 | 7.8 | 0.00 | Jul 21, 2026 | Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: High) | ||
| CVE-2026-14048 | Med | 0.42 | 6.5 | 0.00 | Jun 30, 2026 | Use after free in Chromecast in Google Chrome prior to 150.0.7871.47 allowed an attacker on the local network segment to obtain potentially sensitive information from process memory via a malicious peripheral. (Chromium security severity: Low) | ||
| CVE-2018-12716 | Med | 0.28 | 4.3 | 0.01 | Jun 25, 2018 | The API service on Google Home and Chromecast devices before mid-July 2018 does not prevent DNS rebinding attacks from reading the scan_results JSON data, which allows remote attackers to determine the physical location of most web browsers by leveraging the presence of one of… |
- risk 0.65cvss 10.0epss 0.00
u-boot bug that allows for u-boot shell and interrupt over UART
- risk 0.64cvss 9.8epss 0.00
An oversight in BCB handling of reboot reason that allows for persistent code execution
- risk 0.64cvss 9.8epss 0.01
Remote code execution
- risk 0.64cvss 9.8epss 0.00
Remote code execution
- risk 0.64cvss 9.8epss 0.00
Remote code execution
- risk 0.62cvss 9.6epss 0.00
Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- risk 0.62cvss 9.6epss 0.00
Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
- risk 0.60cvss 9.3epss 0.00
Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: High)
- risk 0.54cvss 8.3epss 0.00
Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
- risk 0.54cvss 8.3epss 0.00
Improper input validation in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
- risk 0.54cvss 8.3epss 0.00
Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
- risk 0.54cvss 8.3epss 0.00
Integer overflow in Chromecast in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
- risk 0.51cvss 7.8epss 0.00
Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: High)
- risk 0.42cvss 6.5epss 0.00
Use after free in Chromecast in Google Chrome prior to 150.0.7871.47 allowed an attacker on the local network segment to obtain potentially sensitive information from process memory via a malicious peripheral. (Chromium security severity: Low)
- risk 0.28cvss 4.3epss 0.01
The API service on Google Home and Chromecast devices before mid-July 2018 does not prevent DNS rebinding attacks from reading the scan_results JSON data, which allows remote attackers to determine the physical location of most web browsers by leveraging the presence of one of…