Executive brief
The Sony XAV-9500ES is a car audio and media player system used in vehicles. A flaw in its USB device authorization rules allows an attacker with physical access to connect a crafted USB device and bypass security restrictions, potentially gaining unauthorized access to device features or functions without requiring authentication.
Technical details
This vulnerability is an authorization bypass affecting the udev rules configuration on the Sony XAV-9500ES. The root cause is improper validation of USB device types, allowing a crafted USB device to trigger instantiation of otherwise restricted USB device categories. The attack vector is physical: an attacker must connect a malicious USB device to the vehicle's head unit. No authentication or user interaction is required. An attacker can leverage this to circumvent authorization controls and access restricted functionality. Sony has released a software update to address this issue.
Affected products
- Sony XAV-9500ES
Timeline
- 2026-03-19: disclosed: Vulnerability reported to vendor
- 2026-07-29: advisory: Coordinated public release
- 2026-07-29: patched: Sony issued software update