From Pwn2Own Automotive 2026: Seven Kenwood DNR1007XR Vulnerabilities Now Patched
Kenwood patched seven DNR1007XR vulnerabilities discovered at Pwn2Own Automotive 2026, addressing direct and multistep paths to root access.
Kenwood patched seven DNR1007XR vulnerabilities discovered at Pwn2Own Automotive 2026, addressing direct and multistep paths to root access.
By decrypting an Android OTA update to their vehicle’s infotainment system, a researcher gained access to proprietary code. We examine the method that the researcher used and what it means for modern vehicle security.
High-impact vulnerabilities in Apple’s AirPlay protocol, collectively known as “AirBorne,” expose CarPlay-equipped vehicles to remote code execution, privacy breaches, and potential system compromise. We explore how the vulnerabilities work, real-world scenarios where exploits could occur, and what users and automotive stakeholders can do to stay protected.
We analyze the three-bug exploit chain demonstrated by security researchers against the Pioneer DMH-WT7600NEX IVI system at Pwn2Own Automotive 2024. We map it to the Automotive Threat Matrix and highlight industry best practices for mitigating similar exploits.
Security researchers uncovered a vulnerability in Subaru’s in-vehicle infotainment (IVI) system admin panel, enabling unauthorized access to personal information, GPS records, and vehicle controls. We examine the findings and emphasize the need for automotive manufacturers to adopt a security-first approach throughout the vehicle lifecycle.
We examine the NCC Group’s two-bug chain during Pwn2Own Automotive 2024, which enabled the team to play Doom on the Alpine Halo9 iLX-F509 IVI system. We underscore the more serious implications once attackers gain root access and recommend countermeasures to mitigate the risks.
The Pwn2Own Automotive 2024 competition uncovered a high-severity zero-click RCE Bluetooth vulnerability in the Alpine Halo9 IVI system, highlighting the risks of proprietary implementations in connected vehicles. We explore the discovery, exploitation techniques, and key takeaways for securing automotive technologies against emerging threats.
The ZDI has identified six zero-day vulnerabilities in an in-vehicle infotainment (IVI) system. As these vulnerabilities remain unpatched, we recommend security best practices to minimize their potential risks and fortify connected vehicles’ IVI systems.
We take a look at Synacktiv’s two-bug chain that successfully exploited Tesla’s in-vehicle infotainment (IVI) system at Pwn2Own Automotive 2024, highlighting security takeaways for enhancing automotive cybersecurity.