CVE-2023-48417 is a critical vulnerability affecting Google Chromecast and its firmware, stemming from missing permission checks in the KeyChainActivity application. This flaw allows unauthorized access and manipulation, carrying a CVSS score of 9.8 (CRITICAL) due to its network-based attack vector, low complexity, and high impact on confidentiality, integrity, and availability. While not yet in CISA's KEV catalog, it has been exploited in hacking contests, indicating active exploitation, and has garnered some community and media attention, including a SecurityWeek article.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2023-10-01CPE matchmatch criteria | cpe:2.3:o:google:chromecast_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.