CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

google

home_firmware

2 known vulnerabilities · sorted by CVSS score

CVE-2023-48419
CRITICAL10.0

An attacker in the wifi vicinity of a target Google Home can spy on the victim, resulting in Elevation of Privilege 

google / nest_audio_firmware+3
Network
Published Jan 2, 2024
CVE-2018-12716
MEDIUM4.3

The API service on Google Home and Chromecast devices before mid-July 2018 does not prevent DNS rebinding attacks from reading the scan_results JSON data, which allows remote attackers to determine the physical location of most web browsers by leveraging the presence of one of these devices on its local network, extracting the scan_results bssid fields, and sending these fields in a geolocation/v1/geolocate Google Maps Geolocation API request.

google / chromecast_firmware+1
Adjacent
Published Jun 25, 2018