Over-the-Air: How we Remotely Compromised the Gateway, BCM, and Autopilot ECUs of Tesla Cars @HackersOnBoard
Over-the-Air: How we Remotely Compromised the Gateway, BCM, and Autopilot ECUs of Tesla Cars  @HackersOnBoard
Uploaded October 2019 | Updated September 2026, 6 hours ago
Black Hat USA 2018

We, Keen Security Lab of Tencent, have successfully implemented two remote attacks on the Tesla Model S/X in year 2016 and 2017. Last year, at Black Hat USA, we presented the details of our first attack chain. At that time, we showed a demonstration video of our second attack chain, but without technical aspects. This year, we are willing to share our full, in-depth details on this research.

In this presentation, we will explain the inner workings of this technology and showcase the new capability that was developed in the Tesla hacking 2017. Multiple 0-days of different in-vehicle components are included in the new attack chain.

We will also present an in-depth analysis of the critical components in the Tesla car, including the Gateway, BCM(Body Control Modules), and the Autopilot ECUs. For instance, we utilized a code-signing bypass vulnerability to compromise the Gateway ECU; we also reversed and then customized the BCM to play the Model X "Holiday Show" Easter Egg for entertainment.

Finally, we will talk about a remote attack we carried out to successfully gain an unauthorized user access to the Autopilot ECU on the Tesla car by exploiting one more fascinating vulnerability. To the best of our knowledge, this presentation will be the first to demonstrate hacking into an Autopilot module.
Over-the-Air: How we Remotely Compromised the Gateway, BCM, and Autopilot ECUs of Tesla CarsBlack Hat USA 2018 - Outsmarting the Smart CityBlack Hat USA 2018 - Meltdown Basics, Details, ConsequencesBlack Hat USA 2018 - An Attacker Looks at Docker Approaching Multi Container ApplicationsBlack Hat USA 2018 - Every ROSE has its Thorn The Dark Art of Remote Online Social EngineeringDEF CON 27 - albinowax - HTTP Desync Attacks Smashing into the Cell Next DoorDEF CON 27 - Jesse Michael - Get Off the Kernel if You Cant DriveDEF CON 27 - Joe Grand Kingpin - Behind the Scenes of the DEFCON 27 BadgeBlack Hat USA 2018 - A Brief History of Mitigation The Path to EL1 in iOS 11Black Hat USA 2018 - Reconstruct the World from Vanished Shadow Recovering Deleted VSS SnapshotsDEF CON 27 - Intro to Embedded Hacking-How you can find a decade old bug in widely deployed devicesBlack Hat USA 2018 - WireGuard Next Generation Secure Network Tunnel
HackersOnBoard |

Over-the-Air: How we Remotely Compromised the Gateway, BCM, and Autopilot ECUs of Tesla Cars

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER