You Hacked My Tesla: Pwn2Own, Exploit Types and Emerging Threat Patterns
Across three days of Pwn2Own Automotive, security researchers demonstrated a sobering reality: modern transportation systems are less like isolated machines and more like rolling networks of vulnerable software. The event showcased vulnerabilities across electric vehicle (EV) chargers, in-vehicle infotainment (IVI) systems, automotive operating systems, and connected infrastructure, revealing that automotive security increasingly resembles enterprise cybersecurity rather than traditional mechanical engineering. While the headlines often emphasize competition outcomes, the more significant takeaway lies in the types of exploits demonstrated and what they reveal about systemic weaknesses.
A dominant theme across the competition was the prevalence of chained exploits, where researchers combined multiple vulnerabilities to achieve deeper compromise. Rather than relying on single catastrophic flaws, attackers stitched together information leaks, memory corruption bugs, and privilege escalation paths to gain root-level access. For example, out-of-bounds writes paired with information disclosure enabled full system compromise in infotainment platforms. This reflects a mature threat model: modern systems may survive isolated bugs, but interconnected software layers create pathways where minor weaknesses accumulate into major failures.
EV chargers emerged as a particularly fruitful attack surface. Researchers repeatedly demonstrated code execution, protocol manipulation, and signal-level attacks against charging stations and controllers. These systems occupy an awkward intersection of operational technology, IoT design, and internet connectivity. They manage authentication, payment, and physical energy delivery, making them both cyber and physical infrastructure targets. Exploits involving charging connector protocols and communication signal manipulation illustrate how vulnerabilities now extend beyond software logic into the trusted interactions between machines. In short, the charger parked next to a vehicle may be as security-critical as the vehicle itself — a development that should concern anyone who assumed cybersecurity ended at the car’s dashboard.
In-vehicle infotainment systems were another recurring weak point. USB-based attacks, navigation receiver compromises, and multimedia system rooting demonstrated that convenience features continue to introduce risk. These platforms often integrate legacy codebases, third-party components, and extensive external interfaces, creating ideal conditions for exploitation. The continued success of local access attacks suggests that physical proximity remains relevant, yet the broader implication is architectural: systems intended for entertainment or user convenience increasingly sit adjacent to trusted automotive networks.
Automotive operating systems, including open and standardized platforms, were also targeted through multi-step exploit chains. These attacks highlight a deeper issue: as automotive software ecosystems adopt modular, update-driven architectures, they inherit complexity traditionally associated with desktop and cloud environments. Security assumptions rooted in isolation and determinism are increasingly difficult to maintain.
Day three coverage emphasized the broader cybersecurity narrative around zero-day vulnerabilities and responsible disclosure timelines. The event reinforced the importance of coordinated disclosure, giving vendors time to patch before public release. Yet it also underscored a difficult truth: zero-day vulnerabilities are not exceptional anomalies but expected outcomes of complex, rapidly evolving systems. Traditional signature-based defenses struggle to detect novel attack paths, requiring behavioral and architectural approaches to defense.
Collectively, the event illustrates a shift in automotive cybersecurity from isolated vehicle hacking toward ecosystem exploitation. The most impactful vulnerabilities were not cinematic “remote car takeover” scenarios but nuanced compromises of peripheral systems — chargers, infotainment devices, and supporting infrastructure. The lesson is quietly unsettling: the attack surface of modern mobility extends well beyond the vehicle itself. In an era where everything is connected, even the mundane devices surrounding transportation may become entry points. The toaster may still be safe for now — but the charger in the garage is definitely part of the battlefield.
References
Ariganello, J. (n.d.). Driving towards zero-days: Hackers take turns uncovering exploits at Pwn2Own. MixMode. https://www.mixmode.ai/blog/driving-towards-zero-days-hackers-take-turns-uncovering-exploits-at-pwn20wn
Trend Micro Research. (2026, January 26). Pwn2Own: Researchers earn $1 million for 76 zero-days. Trend Micro Research. https://www.trendmicro.com/en_us/research/26/a/pwn2own-researchers-earn-1-million-for-76-zero-days.html
Childs, D. (2026, January 22). Pwn2Own Automotive 2026 – Day three results and the Master of Pwn. Zero Day Initiative. https://www.zerodayinitiative.com/blog/2026/1/23/pwn2own-automotive-2026-day-three-results-and-the-master-of-pwn
Comments