An attacker in the wifi vicinity of a target Google Home can spy on the victim, resulting in EoP
CVE-2023-48419

10CRITICAL

Key Information:

Vendor

Google

Vendor
CVE Published:
2 January 2024

What is CVE-2023-48419?

A vulnerability affecting various Google Home devices allows an attacker positioned within the wifi proximity of the target device to exploit system weaknesses. This exploitation could lead to unauthorized observation of users, significantly compromising user privacy and trust. The vulnerability highlights the importance of enhanced security measures in smart home devices to safeguard against potential intrusions.

Affected Version(s)

Google Nest Mini Cast 1.56.356012

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.