CVE ID | Published | Description | Score | Severity |
---|---|---|---|---|
The libcurl CURLOPT_SSL_VERIFYPEER option was disabled on a subset of requests made by Nest production devices which enabled a potential man-in-the-middle attack on requests to Google cloud services by any host the traffic was routed through. | 5.9 |
Medium |
||
An attacker in the wifi vicinity of a target Google Home can spy on the victim, resulting in Elevation of Privilege | 10 |
Critical |