Pwn2Own Automotive 2026: Researchers Score $516,500 For 37 Unique Zero-Days
On the second day of Pwn2Own Automotive 2026, security researchers focused on automotive infotainment systems, EV chargers, and gateways. The event revealed 37 unique zero-day vulnerabilities, resulting in over $516,500 in rewards. This initiative by the…
On the second day of Pwn2Own Automotive 2026, security researchers focused on automotive infotainment systems, EV chargers, and gateways. The event revealed 37 unique zero-day vulnerabilities, resulting in over $516,500 in rewards. This initiative by the Zero Day Initiative (ZDI) highlights critical flaws in vehicle technology, emphasizing the need for vendors to address these vulnerabilities promptly.
Team MAMMOTH, comprising Inhyung Lee, Seokhun Lee, Chulhan Park, Wooseok Kim, and Yeonseok Jang, successfully executed a command injection in the Alpine iLX-F511 head unit, earning $10,000 and 2 Master of Pwn points. Further exploits on the same target by other teams resulted in additional payouts, underscoring weaknesses in Alpine’s firmware.
Julien Cohen-Scali of FuzzingLabs demonstrated an authentication bypass and privilege escalation on the Phoenix Contact CHARX SEC-3150 EV charger, resulting in remote code execution and a $20,000 reward. Fuzzware.io achieved a three-bug chain exploit on Automotive Grade Linux, earning $40,000 and 4 points.
Other notable exploits included command injections and buffer overflows across various devices, including Sony XAV-9500ES and Alpitronic HYC50. These vulnerabilities enabled unauthorized access and control, with significant payouts for the researchers involved.
On the second day of Pwn2Own Automotive 2026, security researchers focused on automotive infotainment systems, EV chargers, and gateways.
The findings from Pwn2Own Automotive 2026 reveal persistent security challenges within connected car ecosystems. Command injections and buffer overflows pose significant risks, allowing unauthorized remote access and control. EV chargers and other automotive technologies remain vulnerable to manipulation and potential attacks.
ZDI's coordination ensures that vendors such as Alpine, Sony, and ChargePoint receive the necessary disclosures to develop patches. The financial rewards and identified vulnerabilities highlight the increasing importance and lucrativeness of addressing automotive cybersecurity issues.
Key recommendations include prioritizing input validation, enhancing authentication mechanisms, and implementing bounded memory operations. Continuous research and systematic vulnerability chaining remain critical in advancing automotive security.
Based on reporting by GBHackers.
