CVE-2024-22004: Google Nest Wifi Point Firmware

High severity, CVSS 7.7. EPSS: 0.2% chance of exploitation in the next 30 days.

Due to length check, an attacker with privilege access on a Linux Nonsecure operating system can trigger a vulnerability and leak the secure memory from the Trusted Application

Affected products

  • Google Nest Wifi Point Firmware: version 24r1 only
  • Google Nest Wifi Pro Firmware: version 24r1 only
  • Google Nest Wifi Router Firmware: version 24r1 only

Published 2024-04-05. Last modified 2026-06-17.