The much-anticipated Pwn2Own Automotive 2025 kicked off today at Tokyo Big Sight, showcasing the cutting edge of automotive cybersecurity research.
On its first day, white-hat hackers demonstrated their skills by exploiting 16 previously unknown vulnerabilities across in-vehicle infotainment (IVI) systems, electric vehicle (EV) chargers, and operating systems (OS). The event awarded a staggering $382,750 in prizes to participants.
Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup - Try for Free
The competition saw a mix of successes, collisions (where exploits overlapped with known vulnerabilities), and failures. Here are the notable achievements:
The standout performance came from PHP Hooligans, who exploited a heap-based buffer overflow on the Autel charger to claim $50,000 and five Master of Pwn points.
Similarly impressive was Sina Kheirkhah, who later exploited a hard-coded cryptographic key vulnerability in a Ubiquiti charger for another $50,000 and five points.
Another notable success came from fuzzware[.]io, whose team accessed an Autel MaxiCharger via an open port and exploited it using a stack-based buffer overflow. Their efforts netted them $25,000 and five points.
Bug collisions—where multiple teams targeted the same vulnerabilities—were a recurring theme. For example:
Despite some failures, such as unsuccessful attempts by Riccardo Mori (Quarkslab) and Sina Kheirkhah on certain targets, the day ended with high spirits.
Pwn2Own Automotive 2025 continues until January 24, with more exploits expected as researchers tackle additional targets. The event underscores the importance of addressing cybersecurity risks in software-defined vehicles as they become increasingly integral to modern transportation.
Integrating Application Security into Your CI/CD Workflows Using Jenkins & Jira -> Free Webinar
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…