Information Disclosure Vulnerability in Sony XAV-9500ES Device
CVE-2026-18278

3.5LOW

Key Information:

Vendor

Sony

Vendor
CVE Published:
20 August 2026

What is CVE-2026-18278?

The Sony XAV-9500ES device contains an Out-Of-Bounds Read vulnerability that can be exploited by network-adjacent attackers to disclose sensitive information. This vulnerability arises from improper validation of Bluetooth L2CAP packets, allowing attackers who can pair a malicious Bluetooth device to read beyond the allocated buffer. This flaw can potentially be leveraged alongside other vulnerabilities, enabling execution of arbitrary code within the device's context.

Affected Version(s)

XAV-9500ES 3.02.0.0

References

CVSS V3.0

Score:
3.5
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.