On the first day of the Pwn2Own Automotive 2026 competition, security researchers exploited 37 zero-days to hack the Tesla Infotainment System and earn $516,500.
After successfully chaining an information leak and an out-of-bounds write vulnerability to obtain root capabilities on the Tesla Infotainment System in the USB-based attack category, Synacktiv Team won $35,000. Additionally, they obtained root-level code execution on the Sony XAV-9500ES digital media receiver by chaining three vulnerabilities, which earned them an extra $20,000 in cash.
PetoWorks received $50,000 for chaining three zero-day bugs to obtain root privileges on a Phoenix Contact CHARX SEC-3150 charging controller, while Teams Fuzzware.io earned an additional $118,000 after hacking an Alpitronic HYC50 Charging Station, an Autel charger, and a Kenwood DNR1007XR navigation receiver read more about Tesla hacked 37 zero-days demoed at Pwn2Own Automotive 2026.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
