#VU112036 Buffer overflow in MIB3 - CVE-2023-28904
Published: June 30, 2025
MIB3
Volkswagen
Description
The vulnerability allows a local attacker to execute arbitrary code on the target system.
The vulnerability exists due to a logic flaw in the bootloader component. An attacker with physical access can trigger memory corruption to bypass firmware signature verification and execute arbitrary code in the infotainment system at boot process.