PT-2018-11350 · Google · Google Home+1
Brannon Dorsey
+1
·
Published
2018-06-25
·
Updated
2018-08-24
·
CVE-2018-12716
CVSS v2.0
3.3
Low
| Vector | AV:A/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Google Home and Chromecast devices (affected versions not specified, but versions before mid-July 2018 are impacted)
Description
The issue concerns a lack of protection against DNS rebinding attacks in the API service of the affected devices. This allows remote attackers to determine the physical location of most web browsers by leveraging the presence of one of these devices on its local network. Attackers can extract the
scan results JSON data, specifically the bssid fields, and send these fields in a "geolocation/v1/geolocate" Google Maps Geolocation API request to obtain location information.Recommendations
For Google Home and Chromecast devices before mid-July 2018, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Chromecast
Google Home