CarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Notification
  • Autonomous Driving
  • Automotive Ethernet
  • BMS
  • ECU
  • EV
  • ISO/SAE 21434
  • Infotainment
  • OTA Updates
  • OBD-II
  • Pwn2Own
  • RCE
  • SDVs
  • TCU
  • UNECE R155
Cybersecurity

St. Paul pulls plate reader cameras after data reached immigration agents

Policy & Compliance

China freezes vehicle software to end patch-later OTA era

Policy & Compliance

NRMA and Lexus Australia push Canberra toward car data law

Policy & Compliance

Quebec report declares car data consent fundamentally broken

Font ResizerAa
CarThreatCarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
Search
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Sign In Sign In
Follow US
© 2026 Carthreat.com. All right reserved.
Cybersecurity

Telecom SudParis VERA tool counts 1,200 CVEs in modern car platforms

Telecom SudParis research finds thousands of known software vulnerabilities in car operating systems, from Android Automotive to QNX

CarThreat Staff
Last updated: July 27, 2026 10:21 am
By
ctadmin
2 Min Read
SHARE

The software running inside modern cars carries a hefty backlog of known security flaws, according to new research from Telecom SudParis. The team built a vulnerability scanner called VERA and tested it against the operating systems powering today’s vehicles, including automotive grade Linux, Android Automotive, QNX, and VxWorks. Standard tools like Trivy produced more than 1,000 false positives on a single image, but VERA filters out findings that only apply to development environments.

Automotive Grade Linux topped the chart with 1,203 documented vulnerabilities in the tested version. Android Automotive posted a similar count. Even safety-certified systems like QNX Neutrino showed 56 known flaws, while VxWorks 7 logged low double digits. Eclipse S-CORE, a leaner stack, came in at just eight.

A high number of documented flaws does not mean a high number of exploitable attack vectors, the researchers caution. Many vulnerabilities live in code that a locked-down vehicle would never expose. The team demonstrated two working attacks to illustrate the gap. One exploited a SQLite bug in Android Automotive. The other targeted the SOME/IP service discovery protocol on Red Hat’s AutoSD and Tesla’s software, successfully knocking a service offline. The same attack failed on Android Automotive because the platform shuffles its port numbers.

The arXiv paper includes the exploit code and a direct argument. Every known vulnerability in these operating systems is technically relevant because modern cars use the same code bases as standard computers. The practical job for security teams is filtering that noise down to what an attacker could realistically reach.

Join Our Newsletter
Subscribe to our newsletter to get our newest articles instantly!
TAGGED:Android AutomotiveAutomotive Grade Linuxautomotive software securityQNX NeutrinoTelecom SudParisvehicle operating system vulnerabilitiesVERA scannerVxWorks
SOURCES:Help Net Security
Share This Article
Facebook Email Copy Link

Follow US

Find US on Social Medias
FacebookLike
XFollow
YoutubeSubscribe

You Might Also Like

Cybersecurity

Dealer-installed alarm exposes 2 million cars to Bluetooth theft attacks

By
ctadmin
July 21, 2026
Cybersecurity

VicOne research reveals ransomware threats targeting global logistics fleets

By
ctadmin
July 18, 2026
Cybersecurity

May Mobility Challenges AV Scaling Norms with Predictive World Model Architecture

By
ctadmin
May 26, 2026
Cybersecurity

Truck recall firmware hid fixes for unlisted security flaws

By
ctadmin
August 6, 2026
Cybersecurity

Mercedes Benz Telemetry Data Replaces Manual Road Surveys for Infrastructure Safety

By
ctadmin
July 21, 2026
CybersecurityElectric Vehicles

E-rickshaw hacking scare exposes cybersecurity flaws in connected EVs

By
ctadmin
July 21, 2026

CarThreat

Intelligence for the EV and automotive security market
  • News
  • Features
  • Spotlight
  • Events
  • About Carthreat
  • Our Mission
  • Services
  • Contact Us
  • OBD-II
  • Automotive Ethernet
  • TCU
  • Infotainment Systems
  • SDVs
  • BMS
  • ECU Security
  • CAN Bus
  • OTA Updates
  • Vulnerabilities
  • Relay Attacks
  • RCE
  • Threat Intelligence
  • Cybersecurity
  • Digital Keys
  • Bluetooth Security
  • ISO/SAE 21434
  • UNECE R155
  • Regulations
  • Data Privacy
  • EVs
  • Autonomous Driving
  • Pwn2Own Automotive

© 2026 Carthreat.com. All right reserved.  Privacy Policy | Legal

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?