Heap Buffer Overflow Vulnerability in Skoda MIB3 Infotainment Unit
CVE-2023-28905
Key Information:
- Vendor
- CVE Published:
- 28 June 2025
What is CVE-2023-28905?
A vulnerability in the image processing binary of the MIB3 infotainment unit in Skoda vehicles can lead to a heap buffer overflow. This potentially allows attackers to execute arbitrary code within the system, posing a significant security risk. Initially identified in the Skoda Superb III with OEM part number 3V0035820, additional affected part numbers can be found in related resources. Given the integration of infotainment systems in modern vehicles, timely remediation is crucial to safeguard against possible exploits.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Volkswagen MIB3 infotainment system MIB3 OI MQB 0 <= 0304
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
