// 2 CRITICAL · 2 ZERO-DAY · 6 CVE · 6 EXPLOIT · 1 ADVISORY NELLE ULTIME 24H
bluetoothCRITICAL

BlueZ: buffer overflow in A2DP consente RCE con privilegi di root

ZDI-26-589 svela una vulnerabilità nello stack Bluetooth BlueZ: stack-based buffer overflow nel modulo A2DP, RCE come root dopo il pai…

25 ago 2026views - 16

CYBERSECCRITICAL

Sony XAV-9500ES: heap overflow AVRCP permette RCE via Bluetooth

La vulnerabilità ZDI-26-475 (CVE-2026-18282, CVSS 8.0) nel parser Bluetooth AVRCP di Sony XAV-9500ES consente esecuzione remota di cod…

12 ago 2026views - 55

VULNCRITICAL

Sony XAV-9500ES: RCE via Bluetooth scoperta a Pwn2Own, fix disponibile

Una vulnerabilità heap-based buffer overflow nel parser AVRCP del Sony XAV-9500ES consente esecuzione remota di codice a un attaccante…

05 ago 2026views - 69

CYBERSECCRITICAL

Sony XAV-9500ES, il Bluetooth diventa arma: dal Pwn2Own al parcheggio

L'advisory ZDI-26-475 documenta un heap-based buffer overflow nel parser AVRCP dell'head unit Sony XAV-9500ES. Sony ha rilasciato il f…

30 lug 2026views - 62

CYBERSEC

Apple Beats: vulnerabilità Bluetooth trasforma cuffie in microfoni spia

Apple ha corretto CVE-2025-20701 nei Beats Studio Buds: attaccanti nel raggio Bluetooth potevano intercettare conversazioni sfruttando…

18 giu 2026views - 103