• News/
  • https://www.bleepingcomputer.com/news/security/tesla-hacked-37-zero-days-demoed-at-pwn2own-automotive-2026/

Tesla hacked, 37 zero-days demoed at Pwn2Own Automotive 2026

BleepingComputer
·
Sergiu Gatlan
·
Published Jan 21, 2026
·
Updated

Security researchers have hacked the Tesla Infotainment System and earned $516,500 after exploiting 37 zero-days on the first day of the Pwn2Own Automotive 2026 competition. Synacktiv Team took home $35,000 after successfully chaining an information leak and an out‑of‑bounds write flaw to get root permissions on the Tesla Infotainment System in the USB-based attack category. They also chained three vulnerabilities to gain root-level code execution on the Sony XAV-9500ES digital media receiver, earning an additional $20,000 cash award. Teams Fuzzware.io collected another $118,000 after hacking an Alpitronic HYC50 Charging Station, an Autel charger, and a Kenwood DNR1007XR navigation receiver, while PetoWorks was awarded $50,000 for chaining three zero-day bugs to gain root privileges on a Phoenix Contact CHARX SEC-3150 charging controller. Team DDOS also earned $72,500 for hacking the ChargePoint Home Flex, the Autel MaxiCharger, and the Grizzl-E Smart 40A vehicle charging station. On the second day of Pwn2Own, the Grizzl-E Smart 40A will be targeted by four teams, the Autel MaxiCharger will be targeted three times, while two teams will attempt to root the ChargePoint Home Flex, each successful attempt bringing the hackers $50,000. Team Fuzzware.io will also attempt to hack the Phoenix Contact CHARX SEC-3150 vehicle charger for a $70,000 cash reward. Vendors have 90 days to develop and release security fixes before TrendMicro's Zero Day Initiative publicly discloses them afte...

Read full article

Affected Software

9 affected components
Tesla Infotainment System
Sony XAV-9500ES
alpitronic HYC50 Charging Station
Autel charger
Kenwood DNR1007XR
Phoenix Contact CHARX SEC-3150
ChargePoint Home Flex
Autel MaxiCharger
Grizzl-E Smart 40A
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What was the main event discussed in the article?

The article discusses the Pwn2Own Automotive 2026 competition where Tesla was hacked by the Synacktiv Team.

2

How many zero-day vulnerabilities were exploited during the competition?

The researchers demonstrated 37 zero-day vulnerabilities in the hacking attempt.

3

Which specific Tesla product was targeted in the hacks?

The Tesla Infotainment System was specifically targeted during the hacking event.

4

What was the total prize money earned by the hackers?

The hackers earned a total of $516,500 for their exploits.

5

What other products or software were mentioned as affected?

Other affected products included devices from Sony, Alpitronic, Autel, Kenwood, and ChargePoint.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203