Executive brief
A vulnerability in the JXL 9-inch Android car infotainment system allows attackers to manipulate the vehicle's reported GPS location. By broadcasting fake GPS signals, an attacker can force the navigation system to display an incorrect or static position. This could lead to navigation failure, operational disruptions, or safety risks if the driver relies on the device for accurate positioning.
Technical details
The JXL infotainment system's GNSS receiver module and location services framework lack integrity validation for incoming satellite signals. An attacker within radio frequency (RF) proximity can use a Software Defined Radio (SDR) to broadcast spoofed GPS signals that override legitimate ones. Because the system does not verify the authenticity of the GNSS input, it accepts the falsified data, resulting in the manipulation of the device's geographic coordinates. While CISA-ADP assigns a CVSS 9.1 (Network), the researcher's analysis suggests an Adjacent vector (AV:A) due to the requirement for RF proximity. No authentication or user interaction is required to execute this attack.
Affected products
- JXL 9 Inch Car Android Double Din Player Android 12.0
Timeline
- 2026-04-07: advisory: NVD publication date