Particle.news
Download on the App Store

Tesla Infotainment Hacked as Pwn2Own Automotive Finds 37 Zero‑Days on Day 1

Vendors now have 90 days under ZDI rules to ship fixes before details go public.

Overview

  • Researchers collected $516,500 in first‑day prizes at the Tokyo contest during Automotive World.
  • The Synacktiv Team used a USB‑based chain of an information leak and an out‑of‑bounds write to gain root on a Tesla infotainment unit, earning $35,000, and later achieved root on a Sony XAV‑9500ES for $20,000.
  • Fuzzware.io earned $118,000 after compromising an Alpitronic HYC50 charging station, an Autel charger, and a Kenwood DNR1007XR navigation receiver.
  • PetoWorks gained root on a Phoenix Contact CHARX SEC‑3150 charging controller for $50,000, while Team DDOS earned $72,500 for hacks on ChargePoint Home Flex, Autel MaxiCharger, and Grizzl‑E Smart 40A chargers.
  • The third annual event features fully patched IVI systems, EV chargers and car OS targets, with 73 security teams competing Jan 21–23 in Tokyo.