ZDI-26-476: (Pwn2Own) Sony XAV-9500ES udev USB Rules Authorization Bypass Vulnerability
Published Jul 29, 2026
·Updated
This vulnerability allows physically present attackers to bypass authorization on affected installations on Sony XAV-9500ES devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 2.4. The following CVEs are assigned: CVE-2026-18283.
Affected Software
1 affected component
Sony XAV-9500ES
Event History
Jul 29, 2026
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-26-476?
The severity of ZDI-26-476 is rated at 2.4 on the CVSS scale.
2
How do I fix ZDI-26-476?
To mitigate ZDI-26-476, ensure that unauthorized physical access to the Sony XAV-9500ES device is restricted.
3
What devices are affected by ZDI-26-476?
ZDI-26-476 specifically affects the Sony XAV-9500ES device.
4
Can ZDI-26-476 be exploited remotely?
No, ZDI-26-476 can only be exploited by physically present attackers.
5
Does ZDI-26-476 require authentication to exploit?
No, ZDI-26-476 does not require authentication to be exploited.