CVE-2026-18283: (Pwn2Own) Sony XAV-9500ES udev USB Rules Authorization Bypass Vulnerability
Sony XAV-9500ES udev USB Rules Authorization Bypass Vulnerability. This vulnerability allows physically present attackers to bypass authorization on affected installations on Sony XAV-9500ES devices. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the udev rules. A crafted USB device connected to the system can trigger instantiation of otherwise restricted USB device types. An attacker can leverage this vulnerability to bypass authorization on the system. Was ZDI-CAN-28992.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Mitigate physically present exploitation by restricting physical access and controlling/monitoring USB device connections to Sony XAV-9500ES systems (e.g., block unauthorized USB device insertion or require approved devices only).
- Compensating control
Apply the mitigation associated with ZDI-CAN-28992 for the Sony XAV-9500ES udev USB Rules Authorization Bypass vulnerability affecting udev rules.
Event History
Frequently Asked Questions
Who is exposed to exploitation?
Affected Sony XAV-9500ES installations are exposed when an attacker can be physically present and connect a crafted USB device to the system. No authentication is required.
What must an attacker do to exploit the issue?
The attacker needs physical access to connect a crafted USB device. The device triggers udev rules that instantiate USB device types that would otherwise be restricted.
What is the security impact of successful exploitation?
Successful exploitation bypasses authorization controls on the system, allowing restricted USB device types to be instantiated. The provided severity information indicates an integrity impact but no stated confidentiality or availability impact.