Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · sony

sony

· 3 Critical

Total CVEs

74

Critical

3

Products

413

Search All CVEs →

74

Products (413)

xav-ax8500 firmware6 CVEsxav-ax85006 CVEskdl-49wd7533 CVEskdl-49wd7543 CVEskdl-49wd7553 CVEskdl-49wd7563 CVEskdl-49wd7573 CVEskdl-49wd7583 CVEskdl-49wd7593 CVEskdl-49we6603 CVEskdl-49we6633 CVEskdl-49we6653 CVEskdl-49we7503 CVEskdl-49we7533 CVEskdl-49we7543 CVEskdl-49we7553 CVEskdl-49wd7513 CVEskdl-49wd7523 CVEsbravia signage3 CVEskd-43xe70003 CVEskd-43xe70023 CVEskd-43xe70033 CVEskd-43xe70043 CVEskd-43xe70053 CVEskd-43xe70733 CVEskd-43xe70773 CVEskd-43xe70933 CVEskd-43xe70963 CVEskd-49xe70003 CVEswd65 firmware3 CVEswd75 firmware3 CVEswe6 firmware3 CVEswe75 firmware3 CVEskd-49xe70023 CVEskd-49xe70033 CVEskd-49xe70043 CVEskd-49xe70053 CVEswf63 CVEswf6 firmware3 CVEswg-c103 CVEswg-c10 firmware3 CVEskd-49xe70733 CVEskd-49xe70773 CVEskd-49xe70933 CVEskd-49xe70963 CVEskd-55xe70003 CVEskd-55xe70023 CVEskd-55xe70033 CVEskd-55xe70043 CVEskd-55xe70053 CVEsplaystation portable3 CVEsr5c firmware3 CVEskd-55xe70733 CVEskd-55xe70773 CVEskd-55xe70933 CVEskd-55xe70963 CVEsxe70 firmware3 CVEsxf703 CVEsxf70 firmware3 CVEskd-65xe70023 CVEskd-65xe70033 CVEskd-65xe70043 CVEskd-65xe70053 CVEskd-65xe70933 CVEskd-65xe70963 CVEskdl-32r500c3 CVEskdl-32r503c3 CVEskdl-32r505c3 CVEskdl-32wd7503 CVEskdl-32wd7513 CVEskdl-32wd7523 CVEssnc-cx600w3 CVEskdl-32wd7533 CVEskdl-32wd7543 CVEskdl-32wd7553 CVEskdl-32wd7563 CVEskdl-32wd7573 CVEskdl-32wd7583 CVEskdl-32wd7593 CVEssnc-eb6003 CVEssnc-eb600b3 CVEssnc-eb602r3 CVEssnc-eb6303 CVEssnc-eb630b3 CVEssnc-eb632r3 CVEskdl-32we6103 CVEskdl-32we6133 CVEssnc-em6003 CVEssnc-em6013 CVEssnc-em602r3 CVEssnc-em602rc3 CVEssnc-em6303 CVEssnc-em6313 CVEssnc-em632r3 CVEssnc-em632rc3 CVEskdl-32we6153 CVEskdl-40r550c3 CVEskdl-40r553c3 CVEskdl-40r555c3 CVEskdl-40wd6503 CVEskdl-40wd6533 CVEskdl-40wd6553 CVEskdl-40we6603 CVEskdl-40we6633 CVEskdl-40we6653 CVEskdl-43wd7503 CVEskdl-43wd7513 CVEskdl-43wd7523 CVEskdl-43wd7533 CVEskdl-43wd7543 CVEskdl-43wd7553 CVEskdl-43wd7563 CVEskdl-43wd7573 CVEskdl-43wd7583 CVEskdl-43wd7593 CVEskdl-43we7503 CVEskdl-43we7533 CVEskdl-43we7543 CVEskdl-43we7553 CVEskdl-48r550c3 CVEskdl-48r553c3 CVEskdl-48r555c3 CVEskdl-48wd6503 CVEskdl-48wd6533 CVEskdl-48wd6553 CVEskdl-49wd7503 CVEsxbr-65x857d2 CVEsxbr-65x900c2 CVEsxbr-65x900e2 CVEsxbr-65x905c2 CVEsxbr-65x907c2 CVEsxbr-65x930c2 CVEsxbr-65x930d2 CVEsxbr-65x930e2 CVEskdl-50w807c2 CVEskdl-50w809c2 CVEskdl-50w820c2 CVEskdl-55w800c2 CVEskdl-55w805c2 CVEskdl-65w850c2 CVEskdl-65w855c2 CVEskdl-65w857c2 CVEskdl-75w850c2 CVEskdl-75w855c2 CVEsxbr-65x935d2 CVEsbravia2 CVEsbravia firmware2 CVEsmusic center2 CVEsxbr-65x937d2 CVEsxbr-65z9d2 CVEsxbr-75x850c2 CVEsxbr-75x850d2 CVEsxbr-75x850e2 CVEsxbr-75x855c2 CVEsxbr-75x855d2 CVEsxbr-75x857d2 CVEsvaio media server2 CVEsxbr-75x900e2 CVEsvaio update2 CVEsxbr-75x910c2 CVEsxbr-75x940c2 CVEsxbr-75x940d2 CVEsxbr-75x940e2 CVEsxbr-75x945c2 CVEsxbr-75z9d2 CVEsxbr-77a1e2 CVEsxbr-85x850d2 CVEsxbr-85x855d2 CVEsxbr-85x857d2 CVEssnc-cx600w firmware2 CVEssnc-eb630 firmware2 CVEssnc-dh120t2 CVEssnc-em632r firmware2 CVEssnc-eb630b firmware2 CVEssnc-em602r firmware2 CVEssnc-eb632r firmware2 CVEssnc-em631 firmware2 CVEsphoto sharing plus2 CVEsplaymemories home2 CVEsplaystation 32 CVEssnc-em602rc firmware2 CVEssnc-em632rc firmware2 CVEssnc-eb600 firmware2 CVEssnc-em600 firmware2 CVEssnc-eb600b firmware2 CVEsxperia xzs2 CVEsxperia xzs firmware2 CVEssnc-em630 firmware2 CVEssnc-eb602r firmware2 CVEssnc-em601 firmware2 CVEsx7500d2 CVEsxav-ax55002 CVEsxav-ax5500 firmware2 CVEskdl-50w805c2 CVEskdl-50w800c2 CVEsxbr-100z9d2 CVEsxbr-43x800d2 CVEsxbr-43x800e2 CVEsxbr-43x830c2 CVEsxbr-49x700d2 CVEsxbr-49x800c2 CVEsxbr-49x800d2 CVEsxbr-49x800e2 CVEsxbr-49x830c2 CVEsxbr-49x835c2 CVEsxbr-49x835d2 CVEsxbr-49x837c2 CVEsxbr-49x839c2 CVEsxbr-49x900e2 CVEsxbr-55a1e2 CVEsxbr-55x700d2 CVEsxbr-55x800e2 CVEsxbr-55x805c2 CVEsxbr-55x806e2 CVEsxbr-55x807c2 CVEsxbr-55x809c2 CVEsxbr-55x810c2 CVEsxbr-55x850c2 CVEsxbr-55x850d2 CVEsxbr-55x855c2 CVEsxbr-55x855d2 CVEsxbr-55x857c2 CVEsxbr-55x857d2 CVEsxbr-55x900c2 CVEsxbr-55x900e2 CVEsxbr-55x905c2 CVEsxbr-55x907c2 CVEsxbr-55x930d2 CVEsxbr-55x930e2 CVEsxbr-65a1e2 CVEsxbr-65x750d2 CVEsxbr-65x800c2 CVEsxbr-65x805c2 CVEsxbr-65x807c2 CVEsxbr-65x809c2 CVEsxbr-65x810c2 CVEsxbr-65x850c2 CVEsxbr-65x850d2 CVEsxbr-65x850e2 CVEsxbr-65x855c2 CVEsxbr-65x855d2 CVEsxbr-65x857c2 CVEsxperia z4 firmware1 CVEsaxruploadserver activex control1 CVEsbravia tv1 CVEscatalyst browse1 CVEscatalyst production suite1 CVEscontent manager assistant1 CVEscontent transfer1 CVEsdigital paper app1 CVEsdvd architect pro1 CVEsdvd architect studio1 CVEsfirst4internet xcp content management1 CVEshap music transfer1 CVEsimagestation1 CVEsmedia go1 CVEsmicro vault fingerprint access software1 CVEsmoviez hd1 CVEsmusic center for pc1 CVEsmylo com 21 CVEsneural network libraries1 CVEsnfc net installer1 CVEsnfc port firmware1 CVEsnfc port software remover1 CVEsp9001 CVEsp900 firmware1 CVEspc\/sc activator for type b1 CVEspcs-xc11 CVEspcs-xc1 firmware1 CVEspcs-xg1001 CVEspcs-xg100 firmware1 CVEspcs-xg100c1 CVEspcs-xg100s1 CVEspcs-xg771 CVEspcs-xg77 firmware1 CVEspcs-xg77c1 CVEspcs-xg77s1 CVEsplaystation 41 CVEsplaystation 4 firmware1 CVEsplaystation 51 CVEsplaystation 5 firmware1 CVEsrc-s3101 CVEsrc-s310\/ed4c1 CVEsrc-s310\/j1c1 CVEsrc-s3201 CVEsrc-s3301 CVEsrc-s3701 CVEsrc-s3801 CVEsrc-s380\/s1 CVEssfcard viewer 21 CVEssmartwi connection utillity1 CVEssnc-ch1151 CVEssnc-ch1201 CVEssnc-ch1601 CVEssnc-ch2201 CVEssnc-ch2601 CVEssnc-cx6001 CVEssnc-dh1201 CVEssnc-dh120t firmware1 CVEssnc-dh1601 CVEssnc-dh2201 CVEssnc-dh220t1 CVEssnc-dh2601 CVEssnc-eb5201 CVEssnc-em5201 CVEssnc-em5211 CVEssnc-ep5201 CVEssnc-ep5211 CVEssnc-ep5501 CVEssnc-ep5801 CVEssnc-er5201 CVEssnc-er5211 CVEssnc-er521c1 CVEssnc-er5501 CVEssnc-er550c1 CVEssnc-er5801 CVEssnc-er5851 CVEssnc-er585h1 CVEssnc-vb6001 CVEssnc-vb600b1 CVEssnc-vb600b51 CVEssnc-vb600l1 CVEssnc-vb6301 CVEssnc-vb63051 CVEssnc-vb63071 CVEssnc-vb632d1 CVEssnc-vb6351 CVEssnc-vm6001 CVEssnc-vm600b1 CVEssnc-vm600b51 CVEssnc-vm600l1 CVEssnc-vm6011 CVEssnc-vm601b1 CVEssnc-vm602r1 CVEssnc-vm6301 CVEssnc-vm63051 CVEssnc-vm63071 CVEssnc-vm6311 CVEssnc-vm632r1 CVEssnc-wr6001 CVEssnc-wr6021 CVEssnc-wr602c1 CVEssnc-wr602cl1 CVEssnc-wr6301 CVEssnc-wr6321 CVEssnc-wr632c1 CVEssnc-xm6311 CVEssnc-xm631l1 CVEssnc-xm6321 CVEssnc-xm6361 CVEssnc-xm6371 CVEssnc-zb5501 CVEssnc-zm5501 CVEssnc-zm5511 CVEssnc-zp5501 CVEssnc-zr5501 CVEssnc ch1401 CVEssnc ch1801 CVEssnc ch2401 CVEssnc ch2801 CVEssnc dh1401 CVEssnc dh140t1 CVEssnc dh1801 CVEssnc dh2401 CVEssnc dh240t1 CVEssnc dh2801 CVEssnc series firmware1 CVEssonicstage connect player1 CVEssonicstage mastering studio1 CVEssony network camera snc-p51 CVEssound forge1 CVEssrs-xb331 CVEssrs-xb33 firmware1 CVEssrs-xb431 CVEssrs-xb43 firmware1 CVEsvaio easy connect1 CVEsvaio manual cybersupport1 CVEsvaio pc wireless lan wizard1 CVEsvaio wireless wizard1 CVEswf-1000x1 CVEswf-1000x firmware1 CVEswf-sp700n1 CVEswf-sp700n firmware1 CVEswh-1000xm21 CVEswh-1000xm2 firmware1 CVEswh-1000xm31 CVEswh-1000xm3 firmware1 CVEswh-ch700n1 CVEswh-ch700n firmware1 CVEswh-h900n1 CVEswh-h900n firmware1 CVEswh-xb7001 CVEswh-xb700 firmware1 CVEswh-xb900n1 CVEswh-xb900n firmware1 CVEswi-1000x1 CVEswi-1000x firmware1 CVEswi-c600n1 CVEswi-c600n firmware1 CVEswi-sp600n1 CVEswi-sp600n firmware1 CVEsxperia 11 CVEsxperia 1 firmware1 CVEsxperia 51 CVEsxperia 5 firmware1 CVEsxperia l11 CVEsxperia l1 firmware1 CVEsxperia pro1 CVEsxperia pro firmware1 CVEsxperia touch1 CVEsxperia touch firmware1 CVEsxperia z41 CVEsaudio usb driver1 CVEs

Recent Vulnerabilities

View all 74
CVE-2020-36924MEDIUM 6.1

Sony BRAVIA Digital Signage 1.7.8 contains a remote file inclusion vulnerability that allows attackers to inject arbitrary client-side scripts through the content material URL parameter. Attackers can exploit this vulnerability to hijack user sessions, execute cross-site scripting code, and modify display content by manipulating the input material type.

CVE-2020-36923CRITICAL 9.8

Sony BRAVIA Digital Signage 1.7.8 contains an insecure direct object reference vulnerability that allows attackers to bypass authorization controls. Attackers can access hidden system resources like '/#/content-creation' by manipulating client-side access restrictions.

CVE-2020-36922HIGH 7.5

Sony BRAVIA Digital Signage 1.7.8 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive system details through API endpoints. Attackers can retrieve network interface information, server configurations, and system metadata by sending requests to the exposed system API.

CVE-2020-36885CRITICAL 9.8

Sony IPELA Network Camera 1.82.01 contains a stack buffer overflow vulnerability in the ftpclient.cgi endpoint that allows remote attackers to execute arbitrary code. Attackers can exploit the vulnerability by sending a crafted POST request with oversized data to the FTP client functionality, potentially causing remote code execution or denial of service.

CVE-2025-64730MEDIUM 6.1

Cross-site scripting vulnerability exists in SNC-CX600W all versions. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the product.

CVE-2025-62497MEDIUM 6.5

Cross-site request forgery vulnerability exists in SNC-CX600W versions prior to Ver.2.8.0. If a user accesses a specially crafted webpage while logged in, unintended operations may be performed.

CVE-2025-5820HIGH 8.8

Sony XAV-AX8500 Bluetooth ERTM Channel Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected Sony XAV-AX8500 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of Bluetooth ERTM channel communication. The issue results from improper channel data initialization. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-26285.

CVE-2025-5479

Sony XAV-AX8500 Bluetooth AVCTP Protocol Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sony XAV-AX8500 devices. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target system in order to exploit this vulnerability. The specific flaw exists within the implementation of the Bluetooth AVCTP protocol. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-26290.

CVE-2025-5478

Sony XAV-AX8500 Bluetooth SDP Protocol Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sony XAV-AX8500 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the Bluetooth SDP protocol. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-26288.

CVE-2025-5477HIGH 7.5

Sony XAV-AX8500 Bluetooth L2CAP Protocol Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Sony XAV-AX8500 devices. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target system in order to exploit this vulnerability. The specific flaw exists within the implementation of the Bluetooth L2CAP protocol. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the elysian-bt-service process. Was ZDI-CAN-26286.

CVE-2025-5476HIGH 8.8

Sony XAV-AX8500 Bluetooth Improper Isolation Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected Sony XAV-AX8500 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of ACL-U links. The issue results from the lack of L2CAP channel isolation. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-26284.

CVE-2025-5475HIGH 7.5

Sony XAV-AX8500 Bluetooth Packet Handling Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Sony XAV-AX8500 devices. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target system in order to exploit this vulnerability. The specific flaw exists within the handling of Bluetooth packets. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before writing to memory. An attacker can leverage this vulnerability to execute code in the context of the elysian-bt-service process. Was ZDI-CAN-26283.

CVE-2024-23972MEDIUM 6.8

Sony XAV-AX5500 USB Configuration Descriptor Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Sony XAV-AX5500 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the USB host driver. A crafted USB configuration descriptor can trigger an overflow of a fixed-length buffer. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-23185

CVE-2024-23922MEDIUM 6.8

Sony XAV-AX5500 Insufficient Firmware Update Validation Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Sony XAV-AX5500 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of software updates. The issue results from the lack of proper validation of software update packages. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-22939

CVE-2022-41796HIGH 7.8

Untrusted search path vulnerability in the installer of Content Transfer (for Windows) Ver.1.3 and prior allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

CVE-2022-3349MEDIUM 6.8

A vulnerability was found in Sony PS4 and PS5. It has been classified as critical. This affects the function UVFAT_readupcasetable of the component exFAT Handler. The manipulation of the argument dataLength leads to heap-based buffer overflow. It is possible to launch the attack on the physical device. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-209679.

CVE-2022-23747CRITICAL 9.8

In Sony Xperia series 1, 5, and Pro, an out of bound memory access can occur due to lack of validation of the number of frames being passed during music playback.

CVE-2022-27094MEDIUM 6.7

Sony PlayMemories Home v6.0 contains an unquoted service path which allows attackers to escalate privileges to the system level.

CVE-2021-20793HIGH 7.8

Untrusted search path vulnerability in the installer of Sony Audio USB Driver V1.10 and prior and the installer of HAP Music Transfer Ver.1.3.0 and prior allows an attacker to gain privileges and execute arbitrary code via a Trojan horse DLL in an unspecified directory.

CVE-2021-38544MEDIUM 5.9

Sony SRS-XB33 and SRS-XB43 devices through 2021-08-09 allow remote attackers to recover speech signals from an LED on the device, via a telescope and an electro-optical sensor, aka a "Glowworm" attack. The power indicator LED of the speakers is connected directly to the power line, as a result, the intensity of a device's power indicator LED is correlative to the power consumption. The sound played by the speakers affects their power consumption and as a result is also correlative to the light intensity of the LEDs. By analyzing measurements obtained from an electro-optical sensor directed at the power indicator LEDs of the speakers, we can recover the sound played by them.

CVE-2020-5589HIGH 8.8

SONY Wireless Headphones WF-1000X, WF-SP700N, WH-1000XM2, WH-1000XM3, WH-CH700N, WH-H900N, WH-XB700, WH-XB900N, WI-1000X, WI-C600N and WI-SP600N with firmware versions prior to 4.5.2 have vulnerability that someone within the Bluetooth range can make the Bluetooth pairing and operate such as changing volume of the product.

CVE-2019-19364HIGH 7.8

A weak malicious user can escalate its privilege whenever CatalystProductionSuite.2019.1.exe (version 1.1.0.21) and CatalystBrowseSuite.2019.1.exe (version 1.1.0.21) installers run. The vulnerability is in the form of DLL Hijacking. The installers try to load DLLs that don’t exist from its current directory; by doing so, an attacker can quickly escalate its privileges.

CVE-2019-15744LOW 3.3

The Sony Xperia Xperia XZs Android device with a build fingerprint of Sony/keyaki_softbank/keyaki_softbank:7.1.1/TONE3-3.0.0-SOFTBANK-170517-0323/1:user/dev-keys contains a pre-installed app with a package name of jp.softbank.mb.tdrl app (versionCode=1413005, versionName=1.3.0) that allows unauthorized wireless settings modification via a confused deputy attack. This capability can be accessed by any app co-located on the device.

CVE-2019-15743MEDIUM 5.5

The Sony Xperia Touch Android device with a build fingerprint of Sony/blanc_windy/blanc_windy:7.0/LOIRE-SMART-BLANC-1.0.0-170530-0834/1:user/dev-keys contains a pre-installed app with a package name of com.sonymobile.android.maintenancetool.testmic app (versionCode=24, versionName=7.0) that allows unauthorized microphone audio recording via a confused deputy attack. This capability can be accessed by any app co-located on the device. This app allows a third-party app to use its open interface to record audio to external storage.

CVE-2019-15416HIGH 7.8

The Sony keyaki_kddi Android device with a build fingerprint of Sony/keyaki_kddi/keyaki_kddi:7.1.1/TONE3-3.0.0-KDDI-170517-0326/1:user/dev-keys contains a pre-installed app with a package name of com.kddi.android.packageinstaller app (versionCode=70008, versionName=08.10.03) that allows other pre-installed apps to perform app installation via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.