Information Disclosure Vulnerability in Sony XAV-9500ES Device
CVE-2026-18278
3.5LOW
What is CVE-2026-18278?
The Sony XAV-9500ES device contains an Out-Of-Bounds Read vulnerability that can be exploited by network-adjacent attackers to disclose sensitive information. This vulnerability arises from improper validation of Bluetooth L2CAP packets, allowing attackers who can pair a malicious Bluetooth device to read beyond the allocated buffer. This flaw can potentially be leveraged alongside other vulnerabilities, enabling execution of arbitrary code within the device's context.
Affected Version(s)
XAV-9500ES 3.02.0.0
