ZDI-26-475: (Pwn2Own) Sony XAV-9500ES AVRCP_Br_Response_Parser Heap-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sony XAV-9500ES devices. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.0. The following CVEs are assigned: CVE-2026-18282.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-475?
The severity of ZDI-26-475 is rated at 77, indicating a high risk for affected systems.
How do I fix ZDI-26-475?
To mitigate ZDI-26-475, update the firmware of the Sony XAV-9500ES to the latest version released by the manufacturer.
What are the consequences of exploiting ZDI-26-475?
Exploiting ZDI-26-475 allows attackers to execute arbitrary code on the Sony XAV-9500ES devices, potentially compromising their functionality.
Who is affected by ZDI-26-475?
ZDI-26-475 affects installations of the Sony XAV-9500ES that allow Bluetooth pairing.
How does ZDI-26-475 work?
ZDI-26-475 works by exploiting a heap-based buffer overflow in the AVRCP_Br_Response_Parser when a malicious Bluetooth device is paired.