Junglewise Threat Intelligence

CVE-2025-63896: JXL Car Infotainment keystroke injection via spoofed Bluetooth HID

CVE-2025-63896 · Severity: high · CVSS 7.6 · Published 2025-12-04

Executive brief

A security vulnerability exists in the JXL 9-inch car infotainment system, which is used for navigation, media, and vehicle settings. An attacker within Bluetooth range can trick the system into recognizing a malicious device as a legitimate keyboard. This allows the attacker to remotely type commands, potentially opening web browsers to malicious sites or altering vehicle settings without the driver's permission.

Technical details

A vulnerability in the Bluetooth Human Interface Device (HID) stack of the JXL infotainment system (Android v12.0) stems from missing authentication for critical functions (CWE-306). An attacker within Bluetooth range can emulate a malicious HID device and bypass pairing security due to minimal confirmation requirements. Once the spoofed keyboard is connected, the attacker can inject arbitrary keystrokes into the Android operating system. This can be used to execute commands, navigate the UI, or trigger web requests, potentially leading to unauthorized data access or system manipulation.

Affected products

  • JXL 9 Inch Car Android Double Din Player 12.0

Timeline

  • 2025-12-04: disclosed: Initial CVE publication
  • 2025-12-04: advisory: NVD entry created

References

Related threats