← Back to feed
Policy & RegulationEmerging1 sourceJul 29, 2026 · 05:00via Zero Day Initiative (Published)

ZDI-26-476: (Pwn2Own) Sony XAV-9500ES udev USB Rules Authorization Bypass Vulnerability

Brief

This vulnerability allows physically present attackers to bypass authorization on affected installations on Sony XAV-9500ES devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 2.

  • The following CVEs are assigned: CVE-2026-18283.
Read more on Zero Day Initiative (Published)