CVE-2023-48424 is a critical U-Boot shell vulnerability affecting Google Chromecast and its firmware, allowing for privilege escalation. With a CVSS score of 9.8, it presents a low-complexity network attack vector leading to complete compromise of confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, this vulnerability was exploited at a hacking contest, indicating real-world applicability, and has garnered some community discussion and media coverage. There is currently no public exploit code available in common frameworks like Metasploit or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2023-10-01CPE matchmatch criteria | cpe:2.3:o:google:chromecast_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.