Executive brief
The Sony XAV-9500ES is a mobile digital media receiver used in vehicles for audio and multimedia control. A heap-based buffer overflow in Bluetooth L2CAP packet processing allows an attacker who pairs a malicious Bluetooth device to execute arbitrary code and take full control of the receiver, potentially compromising user privacy and vehicle safety features.
Technical details
This vulnerability is a heap-based buffer overflow (CWE-122) in the l2_reassemble_sdu function that processes Bluetooth L2CAP (Logical Link Control and Adaptation Protocol) packets. The root cause is insufficient validation of user-supplied packet length before copying data to a heap buffer. The attack requires network-adjacent access (Bluetooth pairing capability) and user interaction (accepting the malicious device pairing). An authenticated attacker can send specially crafted L2CAP packets to trigger the overflow and execute arbitrary code with device privileges. Sony has released an update to address this vulnerability.
Affected products
- Sony XAV-9500ES
Timeline
- 2026-03-19: disclosed: Vulnerability reported to vendor
- 2026-07-29: patched: Coordinated public release and patch availability
- 2026-07-29: advisory: ZDI-26-474 advisory published