Pwn2Own Vancouver 2023, a 3 day hacking contest has concluded today / USA time zone on 24th March, 2023.
France-Based Research Team Synacktiv, an offensive security company (Red Team) has earned 53 points on Day 3 of the contest, netting them prize money of $530,000 and a Tesla Model 3.
Day 1 Video Short – Synacktiv used a time-of-check to time-of-use (TOCTOU) hacking technique to compromise Tesla Model 3 gateway from the ethernet network.
Day 2 Video Short – Synacktiv used a heap overflow and an Out-Of-Bounds (OOB) write to exploit Tesla – Infotainment Unconfined Root.
More related news can be found here:
- https://www.zerodayinitiative.com/blog/2023/3/21/pwn2own-vancouver-schedule-2023
- https://www.teslarati.com/tesla-hackers-win-model-3-pwn2own-2023/amp/
- https://www.securityweek.com/tesla-hacked-twice-at-pwn2own-exploit-contest/
- https://www.bleepingcomputer.com/news/security/microsoft-teams-virtualbox-tesla-zero-days-exploited-at-pwn2own/
- https://www.darkreading.com/vulnerabilities-threats/tesla-model-3-hacked-2-minutes-pwn2own-contest
