Chromecast
by Google
CVEs (8)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-48426 | Cri | 0.65 | 10.0 | 0.00 | Apr 5, 2024 | u-boot bug that allows for u-boot shell and interrupt over UART | ||
| CVE-2023-6181 | Cri | 0.64 | 9.8 | 0.00 | Dec 11, 2023 | An oversight in BCB handling of reboot reason that allows for persistent code execution | ||
| CVE-2022-42541 | Cri | 0.64 | 9.8 | 0.01 | Nov 29, 2023 | Remote code execution | ||
| CVE-2022-42537 | Cri | 0.64 | 9.8 | 0.00 | Nov 29, 2023 | Remote code execution | ||
| CVE-2022-42536 | Cri | 0.64 | 9.8 | 0.00 | Nov 29, 2023 | Remote code execution | ||
| CVE-2026-10884 | Hig | 0.54 | 8.3 | 0.00 | Jun 4, 2026 | Use after free in Chromecast in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | ||
| CVE-2026-9123 | Hig | 0.49 | 7.5 | 0.00 | May 20, 2026 | Heap buffer overflow in Chromecast in Google Chrome on Android, Linux, ChromeOS prior to 148.0.7778.179 allowed a local attacker to execute arbitrary code inside a sandbox via malicious network traffic. (Chromium security severity: Medium) | ||
| CVE-2018-12716 | Med | 0.28 | 4.3 | 0.01 | Jun 25, 2018 | The API service on Google Home and Chromecast devices before mid-July 2018 does not prevent DNS rebinding attacks from reading the scan_results JSON data, which allows remote attackers to determine the physical location of most web browsers by leveraging the presence of one of… |
- risk 0.65cvss 10.0epss 0.00
u-boot bug that allows for u-boot shell and interrupt over UART
- risk 0.64cvss 9.8epss 0.00
An oversight in BCB handling of reboot reason that allows for persistent code execution
- risk 0.64cvss 9.8epss 0.01
Remote code execution
- risk 0.64cvss 9.8epss 0.00
Remote code execution
- risk 0.64cvss 9.8epss 0.00
Remote code execution
- risk 0.54cvss 8.3epss 0.00
Use after free in Chromecast in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
- risk 0.49cvss 7.5epss 0.00
Heap buffer overflow in Chromecast in Google Chrome on Android, Linux, ChromeOS prior to 148.0.7778.179 allowed a local attacker to execute arbitrary code inside a sandbox via malicious network traffic. (Chromium security severity: Medium)
- risk 0.28cvss 4.3epss 0.01
The API service on Google Home and Chromecast devices before mid-July 2018 does not prevent DNS rebinding attacks from reading the scan_results JSON data, which allows remote attackers to determine the physical location of most web browsers by leveraging the presence of one of…