Executive brief
A vulnerability in the Bluetooth firmware of JXL car infotainment systems allows an attacker within wireless range to crash the device. This results in a denial of service, rendering the car's media player and navigation screen unresponsive. The issue affects the JXL 9 Inch Android Double Din Player running version 12.0.
Technical details
A vulnerability exists in the Bluetooth Classic (v5.0) firmware stack of the JXL infotainment system, specifically within the Link Manager Protocol (LMP) implementation. An attacker within Bluetooth range can exploit this by sending crafted LMP packets during the connection setup phase. This triggers an improper resource shutdown or potential buffer overflow in the Bluetooth service, leading to a complete system crash (Denial of Service). The vulnerability is identified as CWE-404 and affects devices running Android version 12.0.
Affected products
- JXL India 9 Inch Car Android Double Din Player firmware 12.0
Timeline
- 2025-12-10: disclosed
- 2025-12-10: advisory