Critical Heap Overflow (CVE‑2026‑18282) in Sony XAV‑9500ES Enables Remote Code Execution via Bluetooth Pairing
What It Is — A heap‑based buffer overflow in the AVRCP_Br_Response_Parser of Sony’s XAV‑9500ES audio‑video receiver allows an attacker who can pair a malicious Bluetooth device to execute arbitrary code on the unit.
Exploitability — CVSS 8.0 (High); network‑adjacent attacker, requires Bluetooth pairing, proof‑of‑concept demonstrated at Pwn2Own.
Affected Products — Sony XAV‑9500ES AV receiver (firmware prior to the July 29 2026 update).
Why It Matters for Compliance & Audit Readiness
- Shows the need for documented access‑control policies that cover Bluetooth and other wireless interfaces (SOC 2 CC6.1).
- Highlights why continuous monitoring of firmware versions is essential evidence for a defensible SOC 2 audit.
- Reinforces the importance of vendor‑risk processes that capture patch status and device‑inventory data for third‑party hardware.
Recommended Actions
- Deploy Sony’s firmware update immediately (see Sony support link).
- Enforce strict Bluetooth pairing policies and maintain an approved‑device inventory.
- Capture firmware‑version and pairing‑log data as audit evidence for SOC 2 logical‑access controls.
Source: Zero Day Initiative advisory