ZDI-CAN-28992: ZDI-26-476: (Pwn2Own) Sony XAV-9500ES udev USB Rules Authorization Bypass Vulnerability
Published Jul 29, 2026
·Updated
This vulnerability allows physically present attackers to bypass authorization on affected installations on Sony XAV-9500ES devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 2.4. The following CVEs are assigned: CVE-2026-18283.
Affected Software
1 affected component
Sony XAV-9500ES
Event History
Jul 29, 2026
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-28992?
The severity of ZDI-CAN-28992 is rated at 2.4 according to the CVSS score.
2
How do I fix ZDI-CAN-28992?
Currently, there is no known patch or fix for the ZDI-CAN-28992 vulnerability, so it is recommended to limit physical access to the device.
3
What devices are affected by ZDI-CAN-28992?
The ZDI-CAN-28992 vulnerability affects Sony XAV-9500ES devices.
4
Is authentication required to exploit ZDI-CAN-28992?
No, authentication is not required to exploit the ZDI-CAN-28992 vulnerability.
5
What type of attack does ZDI-CAN-28992 facilitate?
The ZDI-CAN-28992 vulnerability facilitates an authorization bypass attack on affected installations.