CarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Notification
  • Autonomous Driving
  • Automotive Ethernet
  • BMS
  • ECU
  • EV
  • ISO/SAE 21434
  • Infotainment
  • OTA Updates
  • OBD-II
  • Pwn2Own
  • RCE
  • SDVs
  • TCU
  • UNECE R155
Cybersecurity

St. Paul pulls plate reader cameras after data reached immigration agents

Policy & Compliance

China freezes vehicle software to end patch-later OTA era

Policy & Compliance

NRMA and Lexus Australia push Canberra toward car data law

Policy & Compliance

Quebec report declares car data consent fundamentally broken

Font ResizerAa
CarThreatCarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
Search
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Sign In Sign In
Follow US
© 2026 Carthreat.com. All right reserved.
Car NewsCybersecurity

Pwn2Own automotive 2026 exposes NFC charger and USB infotainment risks

NFC-based charger exploit and USB infotainment attacks highlight expanding connected vehicle attack surface.

CarThreat Staff
Last updated: July 18, 2026 10:04 pm
By
ctadmin
2 Min Read
SHARE

Pwn2Own Automotive 2026 set a new record with 76 unique zero-day vulnerabilities discovered across EV chargers, in-vehicle infotainment systems, and Tesla interfaces. Co-hosted by VicOne and TrendAI Zero Day Initiative in Tokyo, the competition demonstrated three attack surfaces with immediate practical implications for security teams.

For the first time in Pwn2Own history, an NFC tap was used to compromise an EV charger. The Synacktiv team exploited the Autel MaxiCharger AC Elite Home 40A via a stack-based buffer overflow through the NFC interface, achieving code execution that altered the charger’s output behavior. NFC, typically treated as a convenience feature, proved to be an exploitable attack surface when input reaches embedded parsing logic without memory-safety protections.

Hardcoded credentials in EV charger firmware emerged as another critical vector. When credentials are reused across devices or chained with weak update validation, a single compromised charger can cascade into fleet-wide risk. USB interfaces in IVI systems also remain viable attack surfaces when paired with chained memory-safety vulnerabilities.

VicOne recommends security teams treat contactless interfaces with the same validation rigor as network-facing endpoints, implement memory-safe coding practices with compiler-level mitigations, and enforce strict segmentation between convenience features and operational controls.

The findings underscore that the connected vehicle attack surface now extends well beyond the vehicle itself into charging infrastructure and cloud ecosystems.

Join Our Newsletter
Subscribe to our newsletter to get our newest articles instantly!
TAGGED:Automotive SecurityEV Charging SecurityInfotainmentPwn2OwnPwn2Own AutomotiveUSB Attack
SOURCES:Trend Micro
Share This Article
Facebook Email Copy Link

Follow US

Find US on Social Medias
FacebookLike
XFollow
YoutubeSubscribe

You Might Also Like

Cybersecurity

Automotive IQ names its top 20 cybersecurity leaders for 2026

By
ctadmin
July 12, 2026
Developer workstation showing code analysis for QNX embedded systems
Cybersecurity

Unlocking QNX IFS Images for Binary Whitelisting in Automotive Embedded Systems

By
ctadmin
May 25, 2026
CybersecurityEV & Infrastructure

CISA warns of critical flaws in XCharge C6 EV charging stations

By
ctadmin
July 18, 2026
Car News

Functional Model of a Self-Driving Car Control System

By
ctadmin
August 29, 2021
Cybersecurity

Uber and Wayve Launch London Robotaxi Service with Mapless AI System

By
ctadmin
June 12, 2026
Snapdragon Digital Chassis concept illustration of an electric vehicle with glowing internal components
Cybersecurity

Stellantis Pushes Hands-Free Driving With Qualcomm Snapdragon Ride Pilot

By
ctadmin
May 25, 2026

CarThreat

Intelligence for the EV and automotive security market
  • News
  • Features
  • Spotlight
  • Events
  • About Carthreat
  • Our Mission
  • Services
  • Contact Us
  • OBD-II
  • Automotive Ethernet
  • TCU
  • Infotainment Systems
  • SDVs
  • BMS
  • ECU Security
  • CAN Bus
  • Digital Keys
  • Bluetooth Security
  • OTA Updates
  • Vulnerabilities
  • Relay Attacks
  • RCE
  • Threat Intelligence
  • Cybersecurity
  • Autonomous Driving
  • Pwn2Own Automotive
  • ISO/SAE 21434
  • UNECE R155
  • Regulations
  • Data Privacy
  • EVs

© 2026 Carthreat.com. All right reserved.  Privacy Policy | Legal

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?