• News/
  • https://www.bleepingcomputer.com/news/security/hackers-exploit-29-zero-day-vulnerabilities-on-second-day-of-pwn2own-automotive/

Hackers exploit 29 zero-days on second day of Pwn2Own Automotive

BleepingComputer
·
Sergiu Gatlan
·
Published Jan 22, 2026
·
Updated

On the second day of Pwn2Own Automotive 2026, security researchers collected $439,250 in cash awards after exploiting 29 unique zero-days. The Pwn2Own Automotive hacking contest focuses on automotive technologies and takes place this week in Tokyo, Japan, from January 21 to January 23, during the Automotive World auto conference. Throughout the competition, security researchers target fully patched electric vehicle (EV) chargers, in-vehicle infotainment (IVI) systems, and car operating systems (e.g., Automotive Grade Linux). Fuzzware.io currently leads the competition's leaderboard with $213,000 earned after the first two days, and has earned another $95,000 by hacking the Phoenix Contact CHARX SEC-3150 charging controller, the ChargePoint Home Flex EV charger, and the Grizzl-E Smart 40A EV charging station. Sina Kheirkhah of Summoning Team collected another $40,000 after rooting the Kenwood DNR1007XR navigation receiver, the ChargePoint Home Flex, and the Alpine iLX-F511 multimedia receiver. Rob Blakely of Technical Debt Collectors and Hank Chen of InnoEdge Labs were also awarded $40,000 each after demonstrating zero-day exploit chains targeting Automotive Grade Linux and the Alpitronic HYC50 charging station. After the first two days of the contest, security researchers have earned $955,750 in cash awards after exploiting 66 zero-day vulnerabilities. On the third day of Pwn2Own, the Grizzl-E Smart 40A will be targeted again by Slow Horses of Qrious Secure and the PetoWorks...

Read full article

Affected Software

10 affected components
Phoenix Contact CHARX SEC-3150
ChargePoint Home Flex
Grizzl-E Smart 40A
Kenwood DNR1007XR
Alpine iLX-F511
InnoEdge Labs Automotive Grade Linux
alpitronic HYC50
Autel MaxiCharger
Tesla Infotainment System
Sony XAV-9500ES
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the exploitation of 29 zero-day vulnerabilities during the second day of the Pwn2Own Automotive hacking contest.

2

What security implications are discussed in the article?

The article highlights the serious security risks posed by unpatched vulnerabilities in automotive technologies.

3

What products or software are affected by the vulnerabilities?

The affected products include the Phoenix Contact CHARX SEC-3150, ChargePoint Home Flex, Grizzl-E Smart 40A, Kenwood DNR1007XR, Alpine iLX-F511, InnoEdge Labs Automotive Grade Linux, Alpitronic HYC50, Autel MaxiCharger, Tesla Infotainment System, and Sony XAV-9500ES.

4

How much was awarded to security researchers for the exploits?

Researchers collectively earned $439,250 in cash awards for their successful exploits.

5

What is the significance of the Pwn2Own Automotive contest?

Pwn2Own Automotive is a critical event that tests the security of automotive technologies, raising awareness about potential vulnerabilities.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203