logo

Pwn2Own Automotive 2024 - Day Two Results

ID: 3eb7c2d1-46e2-5bce-bf8a-7a1e74bac22b

STIX ID: report--3eb7c2d1-46e2-5bce-bf8a-7a1e74bac22b

Feed Name: Zero Day Initiative (ZDI) Blog

Threat Score
30/100

Date Published: 2024-01-25

Date Updated: 2026-05-01

Author: Dustin Childs

...
...

This bulletin reports outcomes from a security competition where multiple teams demonstrated exploits against embedded and automotive systems: Midnight Blue/PHP Hooligans exploited a Phoenix Contact CHARX SEC-3100 (3-bug chain), Synacktiv exploited a Tesla Infotainment System (2-bug chain), and NCC Group EDG exploited an Alpine Halo9 (2-bug chain); Computest had a successful JuiceBox exploit using a previously known bug, and one competitor failed to complete an Autel MaxiCharger exploit. Rewards and "Master of Pwn" points awarded are listed for each outcome.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.