CVE-2023-6181
https://notcve.org/view.php?id=CVE-2023-6181
An oversight in BCB handling of reboot reason that allows for persistent code execution Un descuido en el manejo del BCB del motivo de reinicio que permite la ejecución persistente del código. • https://source.android.com/docs/security/bulletin/chromecast/2023-12-01 •
CVE-2023-48425
https://notcve.org/view.php?id=CVE-2023-48425
U-Boot vulnerability resulting in persistent Code Execution Vulnerabilidad de U-Boot que resulta en una ejecución de código persistente • https://source.android.com/docs/security/bulletin/chromecast/2023-12-01 •
CVE-2023-48424
https://notcve.org/view.php?id=CVE-2023-48424
U-Boot shell vulnerability resulting in Privilege escalation in a production device Vulnerabilidad del shell U-Boot que provoca una escalada de privilegios en un dispositivo de producción • https://source.android.com/docs/security/bulletin/chromecast/2023-12-01 •
CVE-2023-48417
https://notcve.org/view.php?id=CVE-2023-48417
Missing Permission checks resulting in unauthorized access and Manipulation in KeyChainActivity Application Verificaciones de permisos faltantes que resultan en acceso no autorizado y manipulación en la aplicación KeyChainActivity • https://source.android.com/docs/security/bulletin/chromecast/2023-12-01 • CWE-862: Missing Authorization •
CVE-2018-12716
https://notcve.org/view.php?id=CVE-2018-12716
The API service on Google Home and Chromecast devices before mid-July 2018 does not prevent DNS rebinding attacks from reading the scan_results JSON data, which allows remote attackers to determine the physical location of most web browsers by leveraging the presence of one of these devices on its local network, extracting the scan_results bssid fields, and sending these fields in a geolocation/v1/geolocate Google Maps Geolocation API request. El servicio API en dispositivos Google Home y Chromecast anteriores a mediados de julio de 2018 no evita ataques de reenlace DNS al leer los datos JSON scan_results. Esto permite que atacantes remotos determinen la ubicación física de la mayor parte de navegadores web aprovechando la presencia de uno de estos dispositivos en su red local, extrayendo los campos bssid scan_results y enviándolos en una petición geolocation/v1/geolocate de la API Geolocation de Google Maps. • https://krebsonsecurity.com/2018/06/google-to-fix-location-data-leak-in-google-home-chromecast https://medium.com/%40brannondorsey/attacking-private-networks-from-the-internet-with-dns-rebinding-ea7098a2d325 https://www.tripwire.com/state-of-security/vert/googles-newest-feature-find-my-home https://www.wired.com/story/chromecast-roku-sonos-dns-rebinding-vulnerability • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •