0-CLICK RCE ON THE TESLA INFOTAINMENT THROUGH CELLULAR NETWORK

No ratings

Presented at Offensive Security Conference 2024 by

This talk details the exploit chain demonstrated at pwn2own automotive 2024, showcasing the remote code execution (RCE) on Tesla's infotainment system via the cellular network. The attack compromised two critical systems: the connectivity card, responsible for cellular connectivity, and the infotainment system, controlling the main display in the vehicle. Additionally, the exploit chain includes a Tesla's Linux Security Module bypass and a network sandbox escape, granting the attacker the capability to send legitimate Controller Area Network (CAN) messages and have physical impacts on the car (like openning the doors / trunk / ...).