Executive brief
Sony XAV-9500ES is an in-car multimedia receiver with Bluetooth connectivity. A vulnerability in its Bluetooth packet handling allows an attacker who has paired a malicious Bluetooth device to read sensitive data from device memory. While the reported severity is low, this flaw could be chained with other vulnerabilities to gain control of the device.
Technical details
This is an out-of-bounds read vulnerability in the prh_l2_decode_packet function that handles Bluetooth L2CAP (Logical Link Control and Adaptation Protocol) packets. The root cause is insufficient validation of user-supplied packet data, allowing reads past allocated buffer boundaries. Exploitation requires an attacker to first pair a malicious Bluetooth device with the target XAV-9500ES system, making this a network-adjacent attack. An attacker can leverage this information disclosure in combination with other vulnerabilities to achieve arbitrary code execution on the device. Sony has issued a patch to address this flaw.
Affected products
- Sony XAV-9500ES Not specified
Timeline
- 2026-03-19: disclosed: Vulnerability reported to vendor
- 2026-07-29: advisory: Coordinated public release of advisory ZDI-26-471
- 2026-07-29: patched: Sony released an update