PT-2018-11350 · Google · Google Home+1

Brannon Dorsey

+1

·

Published

2018-06-25

·

Updated

2018-08-24

·

CVE-2018-12716

CVSS v2.0

3.3

Low

VectorAV:A/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Google Home and Chromecast devices (affected versions not specified, but versions before mid-July 2018 are impacted)
Description The issue concerns a lack of protection against DNS rebinding attacks in the API service of the affected devices. This allows remote attackers to determine the physical location of most web browsers by leveraging the presence of one of these devices on its local network. Attackers can extract the scan results JSON data, specifically the bssid fields, and send these fields in a "geolocation/v1/geolocate" Google Maps Geolocation API request to obtain location information.
Recommendations For Google Home and Chromecast devices before mid-July 2018, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-12716

Affected Products

Chromecast
Google Home