ZDI-26-476: (Pwn2Own) Sony XAV-9500ES udev USB Rules Authorization Bypass Vulnerability
This vulnerability allows physically present attackers to bypass authorization on affected installations on Sony XAV-9500ES devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the udev rules. A crafted USB device connected to the system can trigger instantiation of otherwise restricted USB device types. An attacker can leverage this vulnerability to bypass authorization on the system.
Other sources
This vulnerability allows physically present attackers to bypass authorization on affected installations on Sony XAV-9500ES devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 2.4. The following CVEs are assigned: CVE-2026-18283.
— ZDI
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch ZDI-26-476 - Compensating control
Mitigate physically present exploitation by restricting access to the Sony XAV-9500ES device’s USB ports (e.g., physically lock/disable or ensure only authorized personnel can connect USB devices).
Event History
Frequently Asked Questions
What is the severity of ZDI-26-476?
The severity of ZDI-26-476 is rated at 2.4 on the CVSS scale.
How do I fix ZDI-26-476?
To mitigate ZDI-26-476, ensure that unauthorized physical access to the Sony XAV-9500ES device is restricted.
What devices are affected by ZDI-26-476?
ZDI-26-476 specifically affects the Sony XAV-9500ES device.
Can ZDI-26-476 be exploited remotely?
No, ZDI-26-476 can only be exploited by physically present attackers.
Does ZDI-26-476 require authentication to exploit?
No, ZDI-26-476 does not require authentication to be exploited.