Junglewise Threat Intelligence

CVE-2026-18278: Sony XAV-9500ES out-of-bounds read in Bluetooth L2CAP handler

CVE-2026-18278 · Severity: low · CVSS 3.5 · Published 2026-08-20

Technologies: Sony XAV-9500ES. Vendors: Sony.

Executive brief

Sony XAV-9500ES is an in-car multimedia receiver with Bluetooth connectivity. A vulnerability in its Bluetooth packet handling allows an attacker who has paired a malicious Bluetooth device to read sensitive data from device memory. While the reported severity is low, this flaw could be chained with other vulnerabilities to gain control of the device.

Technical details

This is an out-of-bounds read vulnerability in the prh_l2_decode_packet function that handles Bluetooth L2CAP (Logical Link Control and Adaptation Protocol) packets. The root cause is insufficient validation of user-supplied packet data, allowing reads past allocated buffer boundaries. Exploitation requires an attacker to first pair a malicious Bluetooth device with the target XAV-9500ES system, making this a network-adjacent attack. An attacker can leverage this information disclosure in combination with other vulnerabilities to achieve arbitrary code execution on the device. Sony has issued a patch to address this flaw.

Affected products

  • Sony XAV-9500ES Not specified

Timeline

  • 2026-03-19: disclosed: Vulnerability reported to vendor
  • 2026-07-29: advisory: Coordinated public release of advisory ZDI-26-471
  • 2026-07-29: patched: Sony released an update

References

Related threats