CarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Notification
  • Autonomous Driving
  • Automotive Ethernet
  • BMS
  • ECU
  • EV
  • ISO/SAE 21434
  • Infotainment
  • OTA Updates
  • OBD-II
  • Pwn2Own
  • RCE
  • SDVs
  • TCU
  • UNECE R155
Cybersecurity

St. Paul pulls plate reader cameras after data reached immigration agents

Policy & Compliance

China freezes vehicle software to end patch-later OTA era

Policy & Compliance

NRMA and Lexus Australia push Canberra toward car data law

Policy & Compliance

Quebec report declares car data consent fundamentally broken

Font ResizerAa
CarThreatCarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
Search
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Sign In Sign In
Follow US
© 2026 Carthreat.com. All right reserved.
Cybersecurity

Telecom SudParis VERA tool counts 1,200 CVEs in modern car platforms

Telecom SudParis research finds thousands of known software vulnerabilities in car operating systems, from Android Automotive to QNX

CarThreat Staff
Last updated: July 27, 2026 10:21 am
By
ctadmin
2 Min Read
SHARE

The software running inside modern cars carries a hefty backlog of known security flaws, according to new research from Telecom SudParis. The team built a vulnerability scanner called VERA and tested it against the operating systems powering today’s vehicles, including automotive grade Linux, Android Automotive, QNX, and VxWorks. Standard tools like Trivy produced more than 1,000 false positives on a single image, but VERA filters out findings that only apply to development environments.

Automotive Grade Linux topped the chart with 1,203 documented vulnerabilities in the tested version. Android Automotive posted a similar count. Even safety-certified systems like QNX Neutrino showed 56 known flaws, while VxWorks 7 logged low double digits. Eclipse S-CORE, a leaner stack, came in at just eight.

A high number of documented flaws does not mean a high number of exploitable attack vectors, the researchers caution. Many vulnerabilities live in code that a locked-down vehicle would never expose. The team demonstrated two working attacks to illustrate the gap. One exploited a SQLite bug in Android Automotive. The other targeted the SOME/IP service discovery protocol on Red Hat’s AutoSD and Tesla’s software, successfully knocking a service offline. The same attack failed on Android Automotive because the platform shuffles its port numbers.

The arXiv paper includes the exploit code and a direct argument. Every known vulnerability in these operating systems is technically relevant because modern cars use the same code bases as standard computers. The practical job for security teams is filtering that noise down to what an attacker could realistically reach.

Join Our Newsletter
Subscribe to our newsletter to get our newest articles instantly!
TAGGED:Android AutomotiveAutomotive Grade Linuxautomotive software securityQNX NeutrinoTelecom SudParisvehicle operating system vulnerabilitiesVERA scannerVxWorks
SOURCES:Help Net Security
Share This Article
Facebook Email Copy Link

Follow US

Find US on Social Medias
FacebookLike
XFollow
YoutubeSubscribe

You Might Also Like

Cybersecurity

Light-bending film redirects self-driving sensors into oncoming traffic

By
ctadmin
August 10, 2026
Cybersecurity

ZF gives city buses automated steering and suspension for precision docking

By
ctadmin
July 21, 2026
Cybersecurity

Risk scoring framework cuts attack success in autonomous vehicles

By
ctadmin
August 13, 2026
Car NewsCybersecurity

Malware attack forces Japan’s largest taxi company to suspend services

By
ctadmin
July 14, 2026
Cybersecurity

Identity-based crypto removes plaintext keys from CCS charging

By
ctadmin
August 12, 2026
Cybersecurity

Automotive IQ names its top 20 cybersecurity leaders for 2026

By
ctadmin
July 12, 2026

CarThreat

Intelligence for the EV and automotive security market
  • News
  • Features
  • Spotlight
  • Events
  • About Carthreat
  • Our Mission
  • Services
  • Contact Us
  • OBD-II
  • Automotive Ethernet
  • TCU
  • Infotainment Systems
  • SDVs
  • BMS
  • ECU Security
  • CAN Bus
  • Threat Intelligence
  • Cybersecurity
  • Digital Keys
  • Bluetooth Security
  • OTA Updates
  • Vulnerabilities
  • Relay Attacks
  • RCE
  • Data Privacy
  • EVs
  • Autonomous Driving
  • Pwn2Own Automotive
  • ISO/SAE 21434
  • UNECE R155
  • Regulations

© 2026 Carthreat.com. All right reserved.  Privacy Policy | Legal

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?