76 Zero-day Vulnerabilities Uncovered by Hackers on Pwn2Own Automotive 2026
At the Pwn2Own Automotive 2026 event, security researchers identified 76 zero-day vulnerabilities affecting electric vehicle chargers and in-vehicle infotainment systems. The event took place over three days in Tokyo, with a total prize amount of…
At the Pwn2Own Automotive 2026 event, security researchers identified 76 zero-day vulnerabilities affecting electric vehicle chargers and in-vehicle infotainment systems. The event took place over three days in Tokyo, with a total prize amount of $1,047,000 USD. Fuzzware.io emerged as the top performer, earning the Master of Pwn title.
On the first day, 30 entries targeted systems such as the Alpine iLX-F511, Kenwood DNR1007XR, and various EV chargers, uncovering 37 zero-day vulnerabilities. The total payouts for the day amounted to $516,500 USD. Notable achievements include Neodyme AG earning $20,000 for a stack-based buffer overflow on the Alpine iLX-F511, while Fuzzware.io received $50,000 for exploiting an Autel charger using CWE-306 and CWE-347 vulnerabilities.
Additional highlights include SKShieldus's 299 team earning $40,000 for exploiting hardcoded credentials on the Grizzl-E Smart 40A, and PetoWorks receiving $50,000 for a combination of vulnerabilities in the Phoenix Contact CHARX SEC-3150.
The second day added 29 zero-day vulnerabilities and $439,250 USD in rewards, bringing the cumulative results to 66 vulnerabilities and $955,750 USD. Hank Chen from InnoEdge Labs earned $40,000 for exploiting a dangerous method on the Alpitronic HYC50 Lab Mode. Rob Blakely was awarded $40,000 for a combination of out-of-bounds read, memory exhaustion, and heap overflow vulnerabilities on Automotive Grade Linux.
Fuzzware.io continued their success with multiple awards, including $50,000 for exploits on the Phoenix CHARX SEC-3150. Synacktiv and other teams also secured significant rewards for their findings.
The event took place over three days in Tokyo, with a total prize amount of $1,047,000 USD.
The final day concluded with Fuzzware.io securing their lead with a total of 28 points and $215,500 USD in awards. PetoWorks exploited a buffer overflow on the Grizzl-E Smart 40A, earning $10,000, while Viettel Cyber Security received $10,000 for a heap-based buffer overflow vulnerability on the Sony XAV-9500ES.
Juurin Oy demonstrated a TOCTOU vulnerability on the Alpitronic HYC50, earning $20,000. Several partial awards were also given for vulnerabilities in various systems.
High-bounty vulnerabilities, with rewards over $30,000, highlighted critical flaws in chargers and infotainment systems. These vulnerabilities often involved chaining multiple issues, potentially allowing remote code execution or signal manipulation.
Out-of-bounds write on Alpitronic HYC50 Field by Fuzzware.io: $60,000 DoS, race condition, and command injection on Phoenix CHARX SEC-3150 by PetoWorks: $50,000 Exploitation of code execution and signal manipulation on Autel Charger by Fuzzware.io: $50,000
These findings underscore the importance of addressing cybersecurity risks in networked EV chargers and infotainment systems. The Zero Day Initiative coordinates disclosure to vendors to facilitate timely patching, emphasizing the urgency of automotive cybersecurity as electric vehicle adoption increases.
Based on reporting by Cyber Security News.
