CVE-2023-48419: An attacker in the wifi vicinity of a target Google Home can spy on the victim, resulting in EoP
Published Jan 2, 2024
·Updated
An attacker in the wifi vicinity of a target Google Home can spy on the victim, resulting in Elevation of Privilege
Affected Software
8 affected components
All of the following
Google Nest Audio Firmware<2.58
Google Nest Audio
All of the following
Google Nest Mini Firmware<2.58
Google Nest Mini
All of the following
Google Home Mini Firmware<2.58
Google Home Mini
All of the following
Google Home Firmware<2.58
Google Home
Event History
Jan 2, 2024
CVE Published
06:44 PM
Data Sourced
06:44 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-48419?
CVE-2023-48419 is classified as a high-severity vulnerability due to its potential for Elevation of Privilege.
2
How do I fix CVE-2023-48419?
To mitigate CVE-2023-48419, update your Google Nest Audio, Nest Mini, Home Mini, and Home firmware to version 2.58 or later.
3
Who is affected by CVE-2023-48419?
Users of Google Nest Audio, Nest Mini, Home Mini, and Google Home with firmware versions prior to 2.58 are affected by CVE-2023-48419.
4
What are the potential impacts of CVE-2023-48419?
CVE-2023-48419 allows attackers in the vicinity to spy on users, posing a significant privacy risk.
5
Is CVE-2023-48419 a hardware vulnerability?
No, CVE-2023-48419 is a software vulnerability that affects the firmware of certain Google home devices.