Sony XAV-9500ES Vulnerability Allows Local Privilege Escalation
A local privilege escalation vulnerability in Sony's XAV-9500ES infotainment system, demonstrated at Pwn2Own, allows attackers with low-privilege code execution to gain root access.

Security researchers have disclosed a critical local privilege escalation vulnerability affecting Sony's XAV-9500ES infotainment system. The flaw, tracked as ZDI-26-477 and assigned CVE-2026-18284, was successfully demonstrated at the Pwn2Own hacking competition, highlighting its real-world exploitability.
The vulnerability resides within the device's crash dump handler. Specifically, the system fails to adequately validate user-supplied strings before using them in system calls. This oversight allows an attacker who has already gained the ability to execute low-privileged code on the device to exploit the flaw.
By leveraging this weakness, an attacker can escalate their privileges to root level, enabling them to execute arbitrary code with the highest level of system access. This could lead to complete compromise of the device, potentially affecting its functionality and any connected systems or data.
The Zero Day Initiative (ZDI), which coordinated the disclosure, assigned a CVSS score of 7.8 to this vulnerability, classifying it as high severity. The discovery and demonstration at Pwn2Own underscore the sophisticated techniques attackers can employ to target even consumer-grade electronics.
Sony has acknowledged the vulnerability and released a firmware update to address the issue. Users of the XAV-9500ES are strongly advised to apply the available update to protect their devices from potential exploitation. Further details on the patch can be found on Sony's official support website.
The vulnerability was reported to the vendor on March 19, 2026, and the coordinated public release of the advisory occurred on July 29, 2026. The advisory was updated on the same day, indicating ongoing efforts to provide comprehensive information.
The research and disclosure were credited to Synacktiv, a security firm known for its expertise in vulnerability research and penetration testing. Their work highlights the importance of ongoing security testing for connected devices.
This incident serves as a reminder that complex electronic devices, including automotive infotainment systems, can harbor critical vulnerabilities that require prompt patching and vigilant security practices from both manufacturers and consumers.
This advisory details a specific vulnerability, CVE-2026-18283, affecting Sony's XAV-9500ES infotainment system. Unlike the previously reported privilege escalation, this flaw allows physically present attackers to bypass authorization via a crafted USB device, enabling the instantiation of restricted USB device types. Zero Day Initiative assigned a CVSS score of 2.4 to this less severe, but still notable, authorization bypass.
The Zero Day Initiative has published details on a remote code execution vulnerability affecting the Sony XAV-9500ES, assigned CVE-2026-18282. This new advisory, ZDI-26-475, details how attackers can exploit a heap-based buffer overflow in the AVRCP_Br_Response_Parser component by pairing a malicious Bluetooth device. While the previous story focused on privilege escalation, this advisory highlights a distinct remote code execution flaw with a CVSS score of 8.0, and Sony has released a patch for this specific vulnerability.
This new advisory from Zero Day Initiative details a remote code execution vulnerability (CVE-2026-18281) in the same Sony XAV-9500ES devices previously covered. Unlike the prior report which focused on local privilege escalation, this vulnerability allows network-adjacent attackers to achieve RCE after pairing a malicious Bluetooth device, with a CVSS score of 8.0.
This advisory, ZDI-26-473, details a specific buffer overflow vulnerability within the gpsd service of Sony XAV-9500ES devices, identified as CVE-2026-18280. While the existing story mentions a local privilege escalation demonstrated at Pwn2Own, this new information specifies the exact mechanism: a lack of proper length validation when handling NMEA data, allowing physically present attackers to execute arbitrary code in the context of the gpsd daemon without authentication.
This new advisory, ZDI-26-472, details a distinct remote code execution vulnerability in the Sony XAV-9500ES, separate from the previously reported local privilege escalation. The RCE flaw specifically targets the RTSP SETUP functionality, allowing network-adjacent attackers to execute arbitrary code without authentication, whereas the prior vulnerability required local access to escalate privileges.