ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
SUBSCRIBE
ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
ZeroSecurity - Information Security News
No Result
View All Result
Home Exploits

Google Addresses Critical Chromecast Vulnerabilities Exposed in 2023 Hardware Hacking Competition

Kyle by Kyle
December 11, 2023
in Exploits
Reading Time: 2 mins read
Google responds to urgent Chromecast flaws unveiled in 2023 hacking competition, addressing critical vulnerabilities and crediting security researchers.
Share on FacebookShare on Twitter

Last week, Google alerted its users to the fix of Chromecast vulnerabilities, as part of the December Android security updates. The update specifically targets three vulnerabilities affecting AMLogic chips, honing in on the U-Boot subcomponent and a KeyChain issue within the System component.

These vulnerabilities first surfaced in July during the HardPwn USA 2023 hardware hacking competition, held alongside the Hardwear.io conference in California. Notably, Google, Meta, and Parrot products were the focal points of the targeted attacks. At the competition, researchers earned varying amounts ranging from a few hundred dollars to tens of thousands for successfully exploiting Chromecast vulnerabilities.

Acknowledging the efforts of security researchers, Google credited Nolen Johnson of DirectDefense, Jan Altensen, and Ray Volpe for identifying CVE-2023-6181 and CVE-2023-48425. Lennert Wouters, rqu, and Thomas Roth (stacksmashing) were credited for CVE-2023-48424, while Rocco Calvi (TecR0c) and SickCodes were acknowledged for CVE-2023-48417.

DirectDefense shed light on a full Secure Boot exploit chain in a recent blog post, authored by Johnson, Altensen, and Volpe. Despite not disclosing the exact bug bounty amount, the researchers emphasized that their exploit doesn’t directly enable remote code execution. However, it could facilitate an attacker in achieving persistent code execution without the victim’s awareness.

The primary concern, as highlighted by Johnson, revolves around potential supply chain interceptions on platforms like eBay and other third-party retailers. This is particularly worrisome as Android TV streaming boxes obtained through these channels have demonstrated susceptibility to malware injection.

You might also like

Hackers Exploit Maximum-Severity Cisco Zero-Day Bug Since 2023 (CVE-2026-20127)

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

Critical Vulnerabilities Exposed in Ruijie Networks Cloud Platform

The researchers outlined three attack vectors, including eMMC fault injection, Android Verified Boot bypass, and Bootloader Control Block (BCB) persistence method. The BCB persistence method, in particular, enables persistent hacking of the device without the user’s knowledge, emphasizing the vulnerability to supply chain attacks.

TecR0c and Sick Codes revealed that their KeyChain exploit earned them $500, unveiling Android vulnerabilities currently under review by Google. Their exploit, potentially exploitable by any installed application with Intent-sending capabilities, could lead to unauthorized operations and compromise sensitive information.

Wouters, rqu, and Roth detailed a Chromecast exploit earning them over $68,000. Their attack, requiring temporary physical access to the device, is primarily useful for “evil-maid,” supply-chain attacks, and data recovery from lost or stolen devices. By corrupting signals during the boot process, they gained access to the bootloader and executed code with maximum permissions, compromising the Chromecast invisibly to the user.

Previous Post

Apple Report Highlights Surge in Data Breaches, Urges Prioritization of Robust Encryption

Next Post

Ukrainian Hackers Paralyze Russian Taxation Services

Kyle

Kyle

Writer, and editor at ZeroSecurity. Interested in Information Security, the Blockchain, and an overall tech enthusiast. "Formal education will make you a living; self-education will make you a fortune." Contact me here: [email protected]

Recommended For You

Photo of the CISCO logo and text saying "You have been hacked!"

Hackers Exploit Maximum-Severity Cisco Zero-Day Bug Since 2023 (CVE-2026-20127)

March 6, 2026
What is DoubleClickJacking?

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

January 1, 2025

Critical Vulnerabilities Exposed in Ruijie Networks Cloud Platform

December 25, 2024

Vulnerability (CVE-2024-54143 ) Discovered in OpenWrt’s Firmware Upgrade System

December 13, 2024

Cybercriminals Unleash Advanced Phishing-as-a-Service Toolkit Targeting Microsoft 365 Users

November 29, 2024

Major Security Vulnerability Uncovered in qBittorrent Client

November 1, 2024

Related News

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026
KPMG Netherlands Listed as Victim by Nova Ransomware Group

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026
RansomHouse Claims Breach of Key Apple Assembler Luxshare

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026
ZeroSecurity - Information Security News

We cover the latest in technology news, Crypto, Artificial Intelligence, and the threat trends impacting these sectors.

Categories

Piracy

Tutorials

Programming

Malware Analysis

Downloads

  • Contact us
  • Press
  • Writers
  • Privacy Policy
  • Terms of Service

© 2026 ZeroSecurity, All Rights Reserved.

No Result
View All Result
  • Home
  • Security
    • Tools
  • Exploits
  • Data Breaches
  • Malware
  • Privacy
  • Mobile Security
  • Contact Us
    • Press
  • Privacy Policy

© 2026 ZeroSecurity, All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.