From Pwn2Own Automotive 2026: Seven Kenwood DNR1007XR Vulnerabilities Now Patched
Kenwood patched seven DNR1007XR vulnerabilities discovered at Pwn2Own Automotive 2026, addressing direct and multistep paths to root access.
Kenwood patched seven DNR1007XR vulnerabilities discovered at Pwn2Own Automotive 2026, addressing direct and multistep paths to root access.
Pwn2Own Automotive returns to Tokyo in January 2026 for its third edition. Discover the rules, targets, and what’s new in the world’s largest automotive-focused ethical hacking contest.
Traditional vulnerability management platforms overlook zero-day vulnerabilities, putting the automotive industry at risk. Discover how xZETA provides more visibility into vulnerabilities to help the industry stay ahead of emerging threats.
We discuss the two vulnerabilities discovered in the Phoenix Contact CHARX SEC-3100 EV charging controller at Pwn2Own Automotive 2024, highlighting their impact and possible mitigations.
The final day of Pwn2Own Automotive 2025 saw eight unique zero-day vulnerabilities, bringing the total haul for the three-day event to 49. Finishing with 30.5 “Pwn points,” Sina Kheirkhah was crowned this year’s Master of Pwn.
Day two of Pwn2Own Automotive 2025 was a “Tesla EV charger kind of day,” with four Tesla Wall Connectors targeted. The day closed with an impressive haul of 23 unique zero-day vulnerabilities, surpassing the 16 uncovered on day one.
We examine the NCC Group’s two-bug chain during Pwn2Own Automotive 2024, which enabled the team to play Doom on the Alpine Halo9 iLX-F509 IVI system. We underscore the more serious implications once attackers gain root access and recommend countermeasures to mitigate the risks.
We examine a zero-click remote code execution (RCE) vulnerability in Tesla’s tire pressure monitoring system (TPMS), uncovered by Synacktiv researchers at Pwn2Own Vancouver 2024, and highlight its implications for connected vehicle security.
The Pwn2Own Automotive 2024 competition uncovered a high-severity zero-click RCE Bluetooth vulnerability in the Alpine Halo9 IVI system, highlighting the risks of proprietary implementations in connected vehicles. We explore the discovery, exploitation techniques, and key takeaways for securing automotive technologies against emerging threats.
The ZDI has identified six zero-day vulnerabilities in an in-vehicle infotainment (IVI) system. As these vulnerabilities remain unpatched, we recommend security best practices to minimize their potential risks and fortify connected vehicles’ IVI systems.
Google’s Project Zero recently identified a zero-day vulnerability using an AI-assisted framework, marking a promising breakthrough in vulnerability detection. We examine the importance of AI technologies and other strategies in ensuring a more comprehensive approach to automotive cybersecurity.
We take a look at Synacktiv’s two-bug chain that successfully exploited Tesla’s in-vehicle infotainment (IVI) system at Pwn2Own Automotive 2024, highlighting security takeaways for enhancing automotive cybersecurity.
We examine two more Autel MaxiCharger vulnerabilities discovered at Pwn2Own Automotive 2024: CVE-2024-23967 and CVE-2024-23957. Both are classified as a stack-based buffer overflow, a classic yet avoidable programming error that could lead to remote code execution.