PT-2025-31666 · Alpine · Alpine Ilx-507

Moradek

+1

·

Published

2025-01-27

·

Updated

2025-08-18

·

CVE-2025-8474

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Alpine iLX-507 (affected versions not specified)
Description A stack-based buffer overflow vulnerability exists in the Apple CarPlay protocol implementation of the Alpine iLX-507. This flaw allows a physically present attacker to execute arbitrary code on affected devices without authentication. The vulnerability is due to insufficient validation of user-supplied data length before copying it into a fixed-length stack-based buffer, potentially leading to code execution in the context of root.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Stack Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-09487
CVE-2025-8474
ZDI-25-763

Affected Products

Alpine Ilx-507