You can find past Nest Security Bulletins in the archive.
This Nest Security Bulletin contains details of security vulnerabilities that previously affected Google Nest’s connected home devices. The vulnerabilities listed in this bulletin have been addressed. Devices start receiving (Over-the-Air) OTA updates the same month the bulletin is released.
Security Patches
Vulnerabilities are grouped under the device family group and component that they affect. There is a description of the issue and a table with the CVE, associated references, type of vulnerability, and severity.
Vulnerabilities are based on the Common Vulnerabilities and Exposures (CVE) vulnerability naming standard and are organized according to severity, determined by the Common Vulnerability Scoring System (CVSS) standard.
Speakers and Displays
Firmware version 1.56.4.
Firmware is the software installed on your Google Nest device. When a firmware update is available, your device will automatically download the update via an Over-the-Air (OTA) update.
List of Devices included in the update
Nest Hub (2nd gen) |
Nest Audio |
Nest Mini |
Google Home Mini |
Google Home |
Kernel
CVE |
Type |
Severity |
DoS |
High |
|
ID |
High |
|
ID |
High |
|
ID |
High |
|
EoP |
High |
|
EoP |
High |
|
EoP |
High |
|
DoS |
Medium |
|
DoS |
Medium |
|
ID |
Medium |
AMLogic
CVE |
Type |
Severity |
DoS |
High |
|
ID |
High |
Cameras and Doorbells
Firmware version 1.65c.
Firmware is the software installed on your Google Nest device. When a firmware update is available, your device will automatically download the update via an Over-the-Air (OTA) update.
List of Devices included in the update
Kernel
CVE |
Type |
Severity |
RCE |
Critical |
|
EoP |
High |
|
EoP |
High |
|
EoP |
High |
|
EoP |
High |
|
EoP |
High |
|
EoP |
High |
|
EoP |
High |
|
EoP |
High |
|
EoP |
High |
|
EoP |
High |
|
EoP |
High |
|
EoP |
High |
|
EoP |
High |
|
EoP |
High |
|
EoP |
High |
|
EoP |
High |
|
EoP |
High |
|
EoP |
High |
|
EoP |
High |
|
EoP |
High |
|
EoP |
High |
|
EoP |
High |
|
EoP |
High |
|
ID |
High |
|
ID |
High |
|
ID |
High |
|
ID |
High |
|
ID |
High |
|
EoP |
Medium |
WLAN
CVE |
Type |
Severity |
EoP |
Critical |
|
EoP |
High |
|
EoP |
High |
|
DoS |
High |
|
ID |
High |
|
EoP |
High |
|
EoP |
High |
|
ID |
High |
|
EoP |
High |
|
EoP |
Moderate |
|
ID |
Low |
|
ID |
Low |
AMLogic
CVE |
Type |
Severity |
ID |
High |
Common questions and answers
This section answers common questions that may occur after reading this bulletin.
1. How do I determine if my device is updated to address these issues?
Firmware is the software installed on your Google Nest device. When a firmware update is available, your device will automatically download the update via an Over-the-Air (OTA) update.
Find your device's firmware version
2. What do the entries in the Type column mean?
Entries in the Type column of the vulnerability details table reference the classification of the security vulnerability.
Abbreviation |
Definition |
RCE |
Remote code execution |
EoP |
Elevation of privilege |
ID |
Information disclosure |
DoS |
Denial of service |
N/A |
Classification not available |
Get help
Get answers from experts on the Google Nest Community or contact us.