<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Sony Xperia</title>
  <link>https://cvedaily.com/pages/tags/sony-xperia.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/sony-xperia.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Sony Xperia</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:11 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2022-23747 – In Sony Xperia series 1, 5, and Pro, an out of bound memory access can occur due...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23747</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23747</guid>
    <pubDate>Wed, 17 Aug 2022 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-23747</strong></p>
  <p>In Sony Xperia series 1, 5, and Pro, an out of bound memory access can occur due to lack of validation of the number of frames being passed during music playback.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23747">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2019-15744 – The Sony Xperia Xperia XZs Android device with a build fingerprint of Sony/keyak...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-15744</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-15744</guid>
    <pubDate>Thu, 14 Nov 2019 17:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2019-15744</strong></p>
  <p>The Sony Xperia Xperia XZs Android device with a build fingerprint of Sony/keyaki_softbank/keyaki_softbank:7.1.1/TONE3-3.0.0-SOFTBANK-170517-0323/1:user/dev-keys contains a pre-installed app with a package name of jp.softbank.mb.tdrl app (versionCode=1413005, versionName=1.3.0) that allows unauthorized wireless settings modification via a confused deputy attack. This capability can be accessed by…</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-610</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15744">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-15743 – The Sony Xperia Touch Android device with a build fingerprint of Sony/blanc_wind...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-15743</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-15743</guid>
    <pubDate>Thu, 14 Nov 2019 17:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-15743</strong></p>
  <p>The Sony Xperia Touch Android device with a build fingerprint of Sony/blanc_windy/blanc_windy:7.0/LOIRE-SMART-BLANC-1.0.0-170530-0834/1:user/dev-keys contains a pre-installed app with a package name of com.sonymobile.android.maintenancetool.testmic app (versionCode=24, versionName=7.0) that allows unauthorized microphone audio recording via a confused deputy attack. This capability can be accesse…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-610</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15743">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-14983 – The Sony Xperia L1 Android device with a build fingerprint of Sony/G3313/G3313:7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-14983</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-14983</guid>
    <pubDate>Thu, 25 Apr 2019 20:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-14983</strong></p>
  <p>The Sony Xperia L1 Android device with a build fingerprint of Sony/G3313/G3313:7.0/43.0.A.6.49/2867558199:user/release-keys contains the android framework (i.e., system_server) with a package name of android (versionCode=24, versionName=7.0) that has been modified by Sony or another entity in the supply chain. The system_server process in the core android package has an exported broadcast receive…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-14983">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
