CVE-2024-27350

Amazon Fire OS 7 before 7.6.6.9 and 8 before 8.1.0.3 allows Fire TV applications to establish local ADB (Android Debug Bridge) connections. NOTE: some third parties dispute whether this has security relevance, because an ADB connection is only possible after the (non-default) ADB Debugging option is enabled, and after the initiator of that specific connection attempt has been approved via a full-screen prompt.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:amazon:fire_os:*:*:*:*:*:*:*:*
cpe:2.3:o:amazon:fire_os:*:*:*:*:*:*:*:*

History

18 Sep 2025, 16:23

Type Values Removed Values Added
CPE cpe:2.3:o:amazon:fire_os:*:*:*:*:*:*:*:*
First Time Amazon fire Os
Amazon
CWE NVD-CWE-noinfo
References () https://developer.amazon.com/docs/fire-tv/fire-os-overview.html - () https://developer.amazon.com/docs/fire-tv/fire-os-overview.html - Product
References () https://news.ycombinator.com/item?id=39496861 - () https://news.ycombinator.com/item?id=39496861 - Issue Tracking
References () https://www.aftvnews.com/amazon-blocks-long-running-fire-tv-capability-breaking-popular-apps-with-no-warning-and-giving-developers-the-runaround/ - () https://www.aftvnews.com/amazon-blocks-long-running-fire-tv-capability-breaking-popular-apps-with-no-warning-and-giving-developers-the-runaround/ - Exploit, Press/Media Coverage, Third Party Advisory

21 Nov 2024, 09:04

Type Values Removed Values Added
References () https://developer.amazon.com/docs/fire-tv/fire-os-overview.html - () https://developer.amazon.com/docs/fire-tv/fire-os-overview.html -
References () https://news.ycombinator.com/item?id=39496861 - () https://news.ycombinator.com/item?id=39496861 -
References () https://www.aftvnews.com/amazon-blocks-long-running-fire-tv-capability-breaking-popular-apps-with-no-warning-and-giving-developers-the-runaround/ - () https://www.aftvnews.com/amazon-blocks-long-running-fire-tv-capability-breaking-popular-apps-with-no-warning-and-giving-developers-the-runaround/ -

12 Nov 2024, 21:35

Type Values Removed Values Added
Summary
  • (es) Amazon Fire OS 7 anterior a 7.6.6.9 y 8 anterior a 8.1.0.3 permite que las aplicaciones Fire TV establezcan conexiones ADB (Android Debug Bridge) locales. NOTA: algunos terceros cuestionan si esto tiene relevancia para la seguridad, porque una conexión ADB solo es posible después de que la opción Depuración ADB (no predeterminada) esté habilitada y después de que el iniciador de ese intento de conexión específico haya sido aprobado a través de un mensaje en pantalla completa.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.9

26 Feb 2024, 16:28

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-26 16:28

Updated : 2025-09-18 16:23


NVD link : CVE-2024-27350

Mitre link : CVE-2024-27350

CVE.ORG link : CVE-2024-27350


JSON object : View

Products Affected

amazon

  • fire_os