76 Zero-Day Vulnerabilities Exposed at Pwn2Own Automotive 2026 by Hackers
The final day of Pwn2Own Automotive 2026 concluded with significant advancements in identifying security vulnerabilities. Over three days, researchers uncovered and exploited 76 unique zero-day vulnerabilities across various automotive systems, resulting…
The final day of Pwn2Own Automotive 2026 concluded with significant advancements in identifying security vulnerabilities. Over three days, researchers uncovered and exploited 76 unique zero-day vulnerabilities across various automotive systems, resulting in a combined prize pool of $1,047,000 USD.
The team from Fuzzware.io, consisting of Tobias Scharnowski, Felix Buchmann, and Kristian Covic, emerged as the Master of Pwn champions. They earned 28 points and $215,500 USD for their exploits targeting vehicle infotainment and charging systems.
During the competition, a variety of vulnerability types were demonstrated, with buffer overflow exploits being predominant. These included both stack-based and heap-based overflow vulnerabilities, which allowed for arbitrary code execution.
One significant exploit involved Viettel Cyber Security leveraging a heap-based buffer overflow in the Sony XAV-9500ES to gain system control. Additionally, the DDOS team showcased a stack-based overflow in Alpine infotainment systems.
The final day of Pwn2Own Automotive 2026 concluded with significant advancements in identifying security vulnerabilities.
76 Zero-Day Vulnerabilities Exposed (source: Zeroday Initiative)
Furthermore, Juurin Oy's team successfully compromised the Alpitronic HYC50 EV charger using a Time-Of-Check-Time-Of-Use (TOCTOU) race condition vulnerability, earning $20,000 USD and 4 Master of Pwn points. They demonstrated full code execution capabilities by installing a playable version of Doom on the system.
Vulnerabilities were identified across several critical automotive components, including infotainment systems from Alpine, Kenwood, and Sony, as well as EV charging stations from Grizzl-E and Autel. Additionally, permission assignment flaws and race conditions emerged as significant attack vectors.
Exploiting a unique vulnerability to gain root access (source: Zeroday Initiative)
The discovery of these 76 vulnerabilities is expected to drive security improvements across the automotive industry. The findings highlight the need for enhanced security practices in the connected vehicle ecosystem and demonstrate the ongoing attractiveness of automotive systems as targets for researchers. The results will inform coordinated vulnerability management and patching strategies to strengthen the sector's defensive posture.
Based on reporting by GBHackers.
