Executive brief
The Sony XAV-9500ES is a multimedia receiver used in vehicles for audio and media playback. A heap buffer overflow vulnerability in its Bluetooth AVRCP (Audio/Video Remote Control Profile) packet parser allows an attacker who can pair a malicious Bluetooth device to execute arbitrary code on the device, potentially compromising vehicle infotainment system security and user privacy.
Technical details
This vulnerability is a heap-based buffer overflow in the AVRCP_Br_Response_Parser component of the Sony XAV-9500ES. The root cause is insufficient validation of user-supplied data length before copying to a heap buffer, allowing an out-of-bounds write. The attack vector is network-adjacent (Bluetooth); an attacker must first obtain Bluetooth pairing capability with the target device—a precondition that requires physical proximity or social engineering. Successful exploitation allows remote code execution in the device context. Sony has issued a software update to address this vulnerability.
Affected products
- Sony XAV-9500ES
Timeline
- 2026-03-19: disclosed: Vulnerability reported to vendor
- 2026-07-29: advisory: Coordinated public release of advisory ZDI-26-475
- 2026-07-29: patched: Sony issued update