After Tesla returned as a sponsor at the Psw2Own event, researchers at a French cybersecurity company have once again demonstrated that Tesla vehicles’ advanced software and systems are vulnerable to exploitation.
During the Pwn2Own event, Synacktiv was able to hack into the Tesla Model 3 gateway using a Time of Check to Time of Use (TOCTOU) race condition, which involves taking control of the car’s network through its ethernet connection.
However, Synacktiv hacked into a Tesla Model 3 at the event before.
Last year, they were able to exploit the infotainment system but were unable to win the car due to the complexity of the attack. However, this year’s successful TOCTOU attack has earned them $100,000 and ownership of the Tesla Model 3.
Researchers developed a series of exploits that involved a heap overflow and an out-of-band (OBB) write vulnerability on the second day of the event in Vancouver, Canada.
The hack that had Synacktiv earn a cash prize of $250,000 is called an “Unconfined Root”.
Zero Day Initiative (ZDI) announced on Twitter, “CONFIRMED! @Synacktiv used a heap overflow & an OOB write to exploit the Infotainment system on the Tesla. When they gave us the details, we determined they actually qualified for a Tier 2 award! They win $250,000 and 25 Master of Pwn points. 1st ever Tier 2 award. Stellar work!”
Tesla’s involvement in the Pwn2Own event highlights the importance of vehicle security, particularly as electric vehicles are becoming more advanced and connected. With the rapid evolution of technology, it is essential to protect drivers, passengers, and cars from potential cyberattacks.
Recently, Tesla provided information on how they gather and utilise data about their customers and guidelines on accessing and deleting this information.
They encouraged white-hat hackers to test their vehicles’ security systems to identify potential vulnerabilities and improve defence mechanisms to demonstrate their dedication to ensuring the safety of their customers and set a positive example for the automotive industry.
More Stories
Killnet and AnonymousSudan Collaborate to Launch Cyber Attacks on Western Organisations
In recent news, it has been reported that two Russia-sympathetic hacktivist groups, Killnet and AnonymousSudan, have allegedly launched a series...
$4000 Gone In An Instant: Mother Defrauded in Facebook Marketplace Car Deal
A mother of four is warning others to be cautious after believing she had purchased a safe and dependable car...
Shocking Scam: Sydney Family Loses $200K Life-Savings in Suncorp Spoofing Fraud
A family from Sydney has lost their life savings worth $200,000 due to a fraudulent scam. Peter and Madison, who...
Mysterious Money Transfer Leaves Couple Speechless: How They Got an Unsolicited $4000
A young couple in Melbourne claims their bank is making up a personal loan they do not understand. Ashley and...
Phishing + AI + Voice Cloning= Big Trouble: The New Way Criminals are Stealing Your Money
New Alert: Criminals use AI and voice cloning to trick you out of your money. Earlier this year, Microsoft unveiled...
‘Impossible to Spot’ Delivery Scam Email Targets Australia Post Customers – Don’t Fall Victim!
Unsuspecting shoppers should be cautious as a parcel delivery scam that is hard to distinguish targets Australia Post customers. Email...