On July 29, 2026, TrendAI Zero Day Initiative published advisory ZDI-26-475, documenting a remote code execution vulnerability in the Sony XAV-9500ES automotive infotainment system. The flaw, classified as CVE-2026-18282 with a CVSS score of 8.0, resides in the AVRCP_Br_Response_Parser and triggers during the handling of malformed Bluetooth AVRCP packets. Sony had already shipped firmware 3.04.00 on July 16, anticipating the coordinated disclosure by nearly two weeks.
- The ZDI-26-475 vulnerability allows RCE by network-adjacent attackers after pairing a malicious Bluetooth device with the Sony XAV-9500ES system.
- The technical defect is a heap-based buffer overflow in the AVRCP_Br_Response_Parser, caused by a failure to validate user-data length before copying it into memory.
- The discovery occurred in a Pwn2Own context, as confirmed by the explicit tag in the official ZDI listing associated with ZDI-CAN-28995.
- Sony released firmware 3.04.00 on July 16, 2026, acknowledging @ExLuck99 and @gr4ss341 of ANHTUD in collaboration with TrendAI Zero Day Initiative.
How the Attack Works: The AVRCP Parser as Attack Surface
The ZDI advisory describes a linear but effective attack chain. An attacker, positioned in physical proximity to the vehicle, must first complete pairing of a malicious Bluetooth device with the XAV-9500ES unit. Once the connection is established, the device sends AVRCP (Audio/Video Remote Control Profile) packets containing user data of manipulated length. The AVRCP_Br_Response_Parser does not validate this length before copying the data into a heap-allocated buffer, generating an externally controllable overflow.
"This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sony XAV-9500ES devices. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target system in order to exploit this vulnerability." — TrendAI ZDI Advisory ZDI-26-475
The network-adjacent nature of the vector rules out fully remote attacks over the internet, but does not mitigate the risk in real-world scenarios: public parking lots, rest areas, supermarkets, charging stations. The attacker needs meters, not kilometers. The AVRCP profile, designed for remote control of media playback, proves to be a critical attack surface precisely because of its ubiquity in infotainment systems: every automotive Bluetooth stack implements it; few validate it with rigor.
From Pwn2Own to Patch: The Coordinated Disclosure Timeline
The timeline documented by ZDI shows a vendor notification on March 19, 2026, and a coordinated public release on July 29, 2026, an interval of over four months. During this period, Sony developed and tested firmware 3.04.00, released on July 16. The Sony support page states the update "fixes security vulnerabilities in the Bluetooth communication function, Wi-Fi communication function, and USB function" and "enhances the security features of the system software."
The Pwn2Own context emerges explicitly from the official ZDI listing, which associates ZDI-CAN-28995 with the "(Pwn2Own)" tag. Sony formally acknowledges @ExLuck99 and @gr4ss341 of ANHTUD working with TrendAI Zero Day Initiative, confirming the competitive research origin. The Pwn2Own Automotive competition, a specialized branch of the program, has progressively shifted focus from central ECUs toward peripheral components like infotainment and telematics, demonstrating that compromise often begins where security architecture is least layered.
What to Do Now
- Sony XAV-9500ES users must verify installation of firmware 3.04.00 via the device's update system or the official Sony support page.
- Vehicle owners with aftermarket infotainment units must check for model-specific patches, avoiding the assumption that generic updates cover custom Bluetooth stacks.
- Professional integrators and installers should document the firmware version installed on every unit and plan quarterly verification cycles, given that automotive systems receive patches less frequently than consumer devices.
- Organizations with corporate fleets or service vehicles equipped with XAV-9500ES must track adoption of firmware 3.04.00 as an element of their vehicle vulnerability management program.
The Value of a Forgotten Parser: Reading the Case
ZDI's choice to publish full technical details — vulnerable function name, overflow mechanism, protocol involved — contrasts with more opaque advisories and provides a diagnostic framework useful beyond the single product. The AVRCP_Br_Response_Parser is not an exotic component: it is a standard Bluetooth profile implementation, present in dozens of commercial and open-source stacks. Its flaw illustrates a recurring pattern in automotive security: legacy protocols, transported into modern connectivity silos, retain parsing logic developed in eras of different threat models.
The CVSS 8.0 score places the vulnerability in the high-severity band, but not at critical. The gap lies entirely in the pairing prerequisite: an access control that, in theory, filters the attacker. In practice, the history of Pwn2Own research suggests that "physical" prerequisites tend to be underestimated: the parking-lot attacker is a buildable threat model, not a theoretical one. The dimension of risk therefore depends less on the abstract CVSS and more on the probability that a vulnerable vehicle remains unpatched in high-traffic public environments.
The automotive sector faces a structural tension. Vehicle development cycles exceed five years; vulnerability discovery cycles, in a competitive context, are measured in days. Sony's firmware 3.04.00 is a correct response, but its deployment depends on the initiative of the end user or installer, not on silent automatic updates like those of mobile operating systems. This deployment gap, not documented in available sources in terms of adoption rates, remains a critical variable in the residual risk calculation.
Dossier Limits and Open Points
Sources do not specify whether the malicious pairing requires explicit user interaction or if bypass techniques for the association mechanism exist. The privilege level obtained post-exploitation — root access versus limited user context — is not detailed in the ZDI advisory. It is also not clarified whether firmware 3.04.00 fixes exclusively ZDI-26-475 or a broader set of vulnerabilities from the same Pwn2Own batch; Sony's wording groups fixes by communication function without CVE-specific enumeration. Finally, the full CVSS vector string is missing, which would have allowed precise quantification of impact and exploitability components.
FAQ
Is an internet connection required to suffer the attack?
No. The vector is exclusively Bluetooth, with the attacker in physical proximity to the vehicle. No internet connectivity or compromise of external networks is required.
Does firmware 3.04.00 install automatically or require manual action?
Sources do not describe the distribution mechanism. The Sony page presents the firmware as a manual download with installation instructions, suggesting a process requiring initiative from the user or installer.
Are other Sony models affected by the same vulnerability?
The ZDI advisory explicitly mentions XAV-9500ES. Sources neither confirm nor rule out extension to other models sharing the same Bluetooth AVRCP stack.
Information has been verified against cited sources and updated at time of publication.
Sources
- http://www.zerodayinitiative.com/advisories/ZDI-26-475/
- http://www.zerodayinitiative.com/advisories/published/
- https://www.sony.com/electronics/support/mobile-cd-players-digital-media-players-xav-series/xav-9500es/software/00274922