Heap-based Buffer Overflow in Sony XAV-9500ES Bluetooth Device
CVE-2026-18282
8HIGH
What is CVE-2026-18282?
The vulnerability in Sony XAV-9500ES affects the handling of AVRCP packets, allowing attackers to execute arbitrary code through poor validation of user-supplied data. This issue arises when an attacker manages to pair a malicious Bluetooth device with the target system, ultimately exploiting the heap-based buffer overflow flaw that fails to properly verify data length. This can lead to unauthorized access and manipulation of the device.
Affected Version(s)
XAV-9500ES 3.02.00
