Junglewise Threat Intelligence

CVE-2026-18280: Sony XAV-9500ES gpsd buffer overflow arbitrary code execution

CVE-2026-18280 · Severity: low · CVSS 3.9 · Published 2026-08-20

Technologies: Sony XAV-9500ES. Vendors: Sony.

Executive brief

Sony XAV-9500ES is a car media player and receiver with GPS and audio capabilities. This vulnerability allows a physically present attacker to execute arbitrary code on the device by sending specially crafted GPS data through the gpsd daemon. No authentication is required, and successful exploitation could allow an attacker to take complete control of the device's functions.

Technical details

The vulnerability is a classic buffer overflow in the gpsd daemon's NMEA data parsing logic. The root cause is insufficient validation of user-supplied data length before copying it into a fixed-length stack or heap buffer. An attacker with physical access to the vehicle or the ability to inject NMEA GPS sentences (e.g., via a rogue GPS receiver or wireless signal injection) can send oversized payloads to trigger the overflow. The flaw allows arbitrary code execution in the context of the gpsd daemon. Sony has released an update to address this issue.

Affected products

  • Sony XAV-9500ES Not specified

Timeline

  • 2026-03-19: disclosed: Vulnerability reported to vendor
  • 2026-07-29: advisory: Coordinated public release of advisory
  • 2026-07-29: patched: Sony issued an update to correct this vulnerability

References

Related threats