CVE-2023-48426: Chromecast Bootloader & Kernel-level code-execution including compromise of user-data
Published Apr 5, 2024
·Updated
u-boot bug that allows for u-boot shell and interrupt over UART
Affected Software
8 affected components
All of the following
Google Chromecast Firmware=5.0
Any of the following
Google Chromecast Ga00439
Google Chromecast Ga3a00403a14
Google Chromecast H2g2-42
Google Chromecast Nc2-645b
Google Chromecast Nc2-6a5
Google Chromecast Nc2-6a5-d
Google Chromecast Rux-j42
Event History
Apr 5, 2024
CVE Published
via MITRE·03:23 PM
Data Sourced
via MITRE·03:23 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-48426?
CVE-2023-48426 has a significant severity as it exposes the u-boot shell and interrupt capabilities over UART, which can lead to unauthorized access.
2
How do I fix CVE-2023-48426?
To fix CVE-2023-48426, it is recommended to update the Google Chromecast Firmware to a patched version that addresses this vulnerability.
3
Which devices are affected by CVE-2023-48426?
CVE-2023-48426 affects Google Chromecast devices running firmware version 5.0.
4
What are the potential impacts of CVE-2023-48426?
The potential impacts of CVE-2023-48426 include unauthorized access to the device and possible exploitation of the system through the u-boot shell.
5
Is there a workaround for CVE-2023-48426 if I cannot update?
Currently, no effective workaround is recommended for CVE-2023-48426 other than applying the necessary firmware update.