Your in-car entertainment system and EV charger likely have big security flaws, hackers find

Smart Car
(Image credit: 123RF)

Dozens of vulnerabilities have been discovered in vehicle charging systems, in-car entertainment technology and modem subsystems from some of the world’s biggest automotive suppliers, including Tesla. 

The vulnerabilities, which numbered almost 50 in total, were unearthed thanks to the Pwn2Own Automotive hacking competition, which took place during the Automotive World conference in Tokyo earlier this month.

The Pwn2Own concept, which was first launched in 2007, sees some of the world's leading security researchers and 'white hat' hackers gather to find security flaws in consumer technology. As of 2019, the annual competition added connected vehicles and their related infrastructure.

During this year's three-day challenge, the competition quickly uncovered vulnerabilities in Automotive Grade Linux, ChargePoint, JuiceBox, Phoenix Contact, and Ubiquiti Connect EV Station electric vehicle chargers. In-car entertainment systems from Alpine, Pioneer, and Sony (although these tended to be aftermarket head units, rather than manufacturer-fitted devices) and the modem in Tesla vehicles were also highlighted – the latter providing root access, according to Hackster.io.

Further into the competition, additional bugs were found in chargers from Autel and Emporia, bringing the total over three days to 49 "unique zero-day vulnerabilities". The overall prize pot totaled $1 million, but Team Synacktiv unearthed the most security flaws and therefore took the greatest number of points, securing a total winnings of $450,000.

In order to maintain privacy and prevent future attacks, details of the vulnerabilities are kept firmly under wraps. The only information organizers of the Zero Day Initiative (ZDI) unveils is things like "Vudq16 and Q5CA from u0K++ successfully executed a stack-based buffer overflow against the Alpine Halo9 iLX-F509". So not especially helpful for the average car owner, for now.

However, detailed information becomes the property of the ZDI and is subsequently disclosed privately to each of the affected manufacturers, giving them a chance to release patches and avoid future issues.


Analysis: Cars are digital security nightmares

Lexus LF-ZC Concept

(Image credit: Lexus)

One of the most popular buzzwords in automotive right now is the 'software defined vehicle' – a blanket term that relates to the burgeoning amount of connectivity found in modern cars. 

Thanks to the increased data transfer speeds of the 4G and 5G network, the cars on today's roads can be updated remotely, they can 'talk' to existing infrastructure and even other vehicles.

Plug an EV into a public charging station and the vehicle, RFID card and/or smartphone app used during the transaction hands over a bundle of owner information, including names, email addresses and even location, browsing history and online behavioral patterns, according to an article published by the IAPP, the world’s largest global information privacy community.

On top of this, research by Mozilla revealed that modern cars are "the worst product category we have ever reviewed for privacy" thanks to poor practices on data protection, while vulnerabilities in infotainment systems have allowed some security researchers to gain access to restricted vehicle features, such as those premium paid-for features found in Tesla and BMW cars, for example.

More worrying still is the rise in vehicle theft thanks to criminals using sophisticated technology to mimic remote keyless systems. Canada’s Prime Minister, Justin Trudeau, recently announced it is to hold a summit next month to coordinate a national response to a shocking spike in auto thefts across the country in recent years.

Although events like the Pwn2Own Automotive competition help to expose flaws in modern vehicles and their related digital ecosystems, it only really scratches the surface of the privacy and security problems that face modern connected cars. If anything, it serves as further proof that a lot more needs to be done. 

You might also like

Leon Poultney
EVs correspondent

Leon has been navigating a world where automotive and tech collide for almost 20 years, reporting on everything from in-car entertainment to robotised manufacturing plants. Currently, EVs are the focus of his attentions, but give it a few years and it will be electric vertical take-off and landing craft. Outside of work hours, he can be found tinkering with distinctly analogue motorcycles, because electric motors are no replacement for an old Honda inline four.

Read more
Subaru Starlink
Hackers expose serious Subaru security flaws that allow them to remotely start cars
CES 2025 Best EVs
Five CES 2025 EVs that make me excited for the future of transportation
Volkswagen Lane Keep
Over 800,000 electric car owners and drivers may have had private info exposed online
Sony Honda Mobility Afeela 1 screens
The obsession with huge in-car screens has to stop – nobody needs that much information when behind the wheel
Top Android Automotive Apps
The 9 best Android Automotive apps to upgrade your driving experience in 2025
The Volvo EX30 from the front in a yellow color
Finally! The Volvo EX30 has solved one of my biggest problems with modern cars
Latest in Hybrid & Electric Vehicles
Mercedes-Benz CLA 2025
I’ve tried the new Mercedes-Benz Superscreen – and its Google Gemini-powered smarts push EV infotainment to the next level
The Toyota FT-Me Concept sitting in a car park
Toyota's self-charging concept EV could help you tackle the daily commute on solar power alone
Rivian R1T
Big Rivian update delivers hands-off driving to rival Tesla Autopilot – and a new 'Rally' mode
The Deepal EO7 from the side, an SUV and pick-up truck combo
I drove an electric SUV that transforms into a pick-up, and it’s as fun as it is functional
Tesla Model 3
Tesla's EV sales are plummeting – as used Model Y and Model 3 prices crash to bargain levels
Telo MT1
The anti-Cybertruck? This new electric pick-up is the size of a Mini and the cutest way to haul your gear
Latest in News
Super Mario Odyssey
ChatGPT is the ultimate gaming tool - here's 4 ways you can use AI to help with your next playthrough
Brad Pitt looks over his right shoulder with 'F1' written behind him
Apple Original Films will take you behind-the-scenes of a racing cockpit in this new thrilling F1 movie trailer
AI writer
Coding AI tells developer to write it himself
Reacher looking down at another character from the Prime Video TV series Reacher
Reacher season 3 becomes Prime Video’s biggest returning show thanks to Hollywood’s biggest heavyweight
Finger Presses Orange Button Domain Name Registration on Black Keyboard Background. Closeup View
I visited the world’s first registered .com domain – and you won’t believe what it’s offering today
Image showing detail of the Leica D-Lux 8
Still can't get a Fujifilm X100VI? This premium Leica compact costs less, and it's in stock