Blog

Under Pressure: Exploring a Zero-Click RCE Vulnerability in Tesla’s TPMS

Under Pressure: Exploring a Zero-Click RCE Vulnerability in Tesla’s TPMS

We examine a zero-click remote code execution (RCE) vulnerability in Tesla’s tire pressure monitoring system (TPMS), uncovered by Synacktiv researchers at Pwn2Own Vancouver 2024, and highlight its implications for connected vehicle security.

From Pwn2Own Automotive: A High-Severity Zero-Click RCE Bluetooth Vulnerability in the Alpine Halo9 IVI System

From Pwn2Own Automotive: A High-Severity Zero-Click RCE Bluetooth Vulnerability in the Alpine Halo9 IVI System

The Pwn2Own Automotive 2024 competition uncovered a high-severity zero-click RCE Bluetooth vulnerability in the Alpine Halo9 IVI system, highlighting the risks of proprietary implementations in connected vehicles. We explore the discovery, exploitation techniques, and key takeaways for securing automotive technologies against emerging threats.

GenAI Takes the Wheel: Can Automotive Cybersecurity Keep Up?

GenAI Takes the Wheel: Can Automotive Cybersecurity Keep Up?

Qualcomm has taken a significant step toward bringing GenAI to vehicles by integrating its next-generation Oryon processor into in-car systems. We explore the technology powering GenAI, highlighting what makes it so transformative — and the security challenges it introduces.

Security Mitigations for the Multiple Zero-Day Vulnerabilities Discovered in an IVI System

Security Mitigations for the Multiple Zero-Day Vulnerabilities Discovered in an IVI System

The ZDI has identified six zero-day vulnerabilities in an in-vehicle infotainment (IVI) system. As these vulnerabilities remain unpatched, we recommend security best practices to minimize their potential risks and fortify connected vehicles’ IVI systems.

Exploiting the Emporia EV Charger: A Hacker’s Point of View

Exploiting the Emporia EV Charger: A Hacker’s Point of View

Exposed serial interfaces in electric vehicle (EV) chargers present a significant vulnerability, enabling attackers to tamper with hardware and firmware. This creates opportunities for malicious activities, highlighting the need for strong security measures to prevent such exploits.

From Pwn2Own Automotive: More Stack-Based Buffer Overflow Vulnerabilities in Autel MaxiCharger

From Pwn2Own Automotive: More Stack-Based Buffer Overflow Vulnerabilities in Autel MaxiCharger

We examine two more Autel MaxiCharger vulnerabilities discovered at Pwn2Own Automotive 2024: CVE-2024-23967 and CVE-2024-23957. Both are classified as a stack-based buffer overflow, a classic yet avoidable programming error that could lead to remote code execution.

Previous
1 ... 4 5 6 7 8 ... 14
Next