Executive brief
The Sony XAV-9500ES is an in-vehicle media player and entertainment system. A vulnerability in its crash dump handling mechanism allows attackers with low-level system access to inject arbitrary commands that execute with root privileges, potentially giving them complete control over the device and any connected data or functions.
Technical details
The vulnerability is a command injection flaw in the crash dump handler of the Sony XAV-9500ES. It stems from insufficient validation of user-supplied input before passing it to a system call. An attacker who has already obtained the ability to execute low-privileged code can craft a malicious input that breaks out of the intended command context and injects arbitrary shell commands. When the crash dump handler processes this input, the injected commands execute with root privileges, allowing full privilege escalation and arbitrary code execution. A patch has been released by Sony.
Affected products
- Sony XAV-9500ES
Timeline
- 2026-03-19: disclosed: Vulnerability reported to vendor
- 2026-07-29: patched: Sony issued an update; coordinated public release
- 2026-07-29: advisory: ZDI-26-477 advisory published