Submind YouTube summaries
Thumbnail for DEF CON 34 - Video Team - Car Hacking Villlage

DEF CON 34 - Video Team - Car Hacking Villlage

Watch on YouTube

Video summary

The video takes place inside a 2025 electric Volkswagen bus at DEF CON 34, where security researchers discuss various attack vectors targeting modern vehicles. The primary entry points identified include USB ports and Bluetooth stacks, which often contain proprietary vulnerabilities that can be exploited without user interaction or authentication. By connecting an infected device via these interfaces, attackers could gain direct access to the infotainment system, allowing them to perform lateral movement across other electronic control units within the car. This level of compromise enables malicious actors to unlock doors, start or stop the engine, and even record audio from interior microphones, effectively turning a connected feature into a critical security weakness. A particularly alarming example highlighted involves a low-energy Bluetooth device installed in many California vehicles intended to enhance security but which ironically created new vulnerabilities. Researchers demonstrated that within a range of approximately 20 meters, an attacker could exploit memory corruption flaws in the proprietary stack to hack cars without needing any credentials or physical access. Although patches have since been released for this specific issue, the incident revealed how widespread the vulnerability was before mitigation, affecting up to ninety percent of affected vehicles and proving that security-focused hardware can sometimes introduce significant risks if not rigorously tested against real-world attack scenarios like man-in-the-middle attacks on EV charger communication protocols. The discussion further explores advanced techniques such as brute-forcing rolling code systems designed to prevent replay attacks in keyless entry mechanisms. By analyzing the frequency frames sent between the fob and the vehicle, attackers can potentially bypass these countermeasures entirely, effectively neutralizing the protection offered by modern anti-replay technologies. This capability means that even with sophisticated security features like rolling codes, a determined adversary could duplicate keys or unlock vehicles remotely without possessing the physical key fob. The researchers emphasize that such exploits are not just theoretical but have been successfully tested on very recent models from 2025 and potentially future years like 2026, underscoring the urgent need for continuous security updates in automotive software ecosystems. In conclusion, the session serves as a stark reminder of the evolving landscape of car hacking where convenience features often expand the attack surface rather than reduce it. The ability to access critical vehicle functions through seemingly benign connections like Bluetooth or USB ports illustrates why manufacturers must prioritize secure coding practices and transparent vulnerability disclosure over proprietary obfuscation that hinders independent security audits. As vehicles become increasingly interconnected with external networks, ensuring robust defenses against zero-click exploits becomes essential for protecting both consumer privacy and physical safety on the road.
Read the full video transcript
We are in the car hacking village. I am here with Reverse Everything and Bitbang. We are inside of a VW bus uh 2025 electric. Right, tell us a little bit about the exploits of what we're looking at here. We're going to talk about some vector points of things that you would want to hit and other exploits. >> Sure. Nice to meet you guys. So here we have a lot of attack vectors in nowadays the car have a lot of attack vectors. Here we have a USBC port right here we have in this car three USBC ports and this is an attack vectors for malicious actors because h there could be like in the USB stacks probably should be uh vulnerabilities right and also another attack vector that is very exploited it is the Bluetooth right in the most of the cases the Bluetooth stack is proprietary that's the reason that the the attack that attackers hack this the another attack vector as well and the people don't know about that is about the radio frequency and the radio frequency is like the key fob, the TPMS, you know, the tire precious monitor system and also about the telematic control unit that is connected to a basis station is also another type vector frequency as well. So h there are more and right now in this car this is like a post bagging ID bus we have a EV charger and right now is like very popular this kind of res in the EV charger because this PLC communication that when you connect it's not just voltage it's not just current it's frames travel between the station and the car and this is very dangerous because maybe there is like man in the middle attacks and this kind of things so has a very quite interesting problem. For example, some CVEs that are found in the Bluetooth proprietary sts about h memory corruption. So for example h if I connect my phone and I have this basically I can get access to the infotainment system. I can get access a reshelf h with a zero click or one click. When I mention zero click is without authentication, without touching the screen, without touching the screen the and even worse without touching the the without touching things is like a zero click, right? And yeah, this is like this kind of exploits that literally you get access to the car and after that you can do lateral movement to the another electronic control unit and you can unlock the car, stop the car, power on the motor, kill the motor >> through infotainment >> through the infotainment system. Yeah. Yeah. Yeah. It's like the the main part. >> Got it. That's pretty serious. We're we're sitting in traffic, right? Um I have the Bluetooth on pairing. Um, is there potential like you could be sitting in a car next to this car and run an attack? >> Yeah, that's very good because and that's a very good point because honestly like one more appear something in San in California appears there's like a in the California the cars by default sell you with a device that allow you to protect your car and this device is connected to all the canvas. It's is it's this like uh it's not a mandatory but you can say hey I don't want that but if you don't say that it doesn't really matter because this device is already installed they disabled that and this new was very cool because this art just appeared one ago or maybe three weeks ago because this is through Bluetooth right and there is like a guy there's a documental invite to to see this there's a documental that there's like a guide with a car looking for how many cars have this device through Bluetooth. So they discovered this through Bluetooth. They discovered using approach like around maybe 20 m uh they was able to hack a car in a radio of 20 m. So he was driving a car with this sniffing what are the cars that have this vulnerable device and right now in California there are many many cars that have this. The update is already exist. The the update the patch already exist. But one more ago anyone absolutely anyone without a without authentication without knowing just the was necessary to stay like 20 m 10 m you know in the to low energy range and he was able to to to hack the car, unlock the car, start the car, record car, the microphone, everything. Everything. >> Dang. That vulnerability was just patched like a month ago. So that was >> Yeah. So there was a new in California all the maybe the 90% of the cars was vulnerable to this. And this is insane because this device was created for do security in the car but this is security create insecurity. >> It was the vulnerability itself. >> Yeah. Yeah. >> That's crazy. Which leads me to so I know you are doing a talk on Sunday um how to get into cars without the key fob. Correct. >> Yeah, sure. >> Talk to me, man. What do we got? What are you going to be really bringing up with that vulnerability? >> Yeah, I'm I'm pretty excited about that because we are going to do like a brute force to the rolling code. Rolling code is the um security system that allow you to protect your car in order to avoid a replay and in the middle attack. So, each time you press the button, you have a different con that going to unlock the car. But what happen if I discover the way to communicate and the way to with the frame and send the frame to write a frequency and do the brute force attack to the counter or to the random part basically and if we mix this with another vulnerability h basically we can duplicate the key fob and after that unlock the car without the key fob or even in 2026 car 2025 cars >> that's even with like a rolling code that you you're able to still >> Yeah exactly it's like hug the rolling code like completely completely kill the rolling code. >> That's that's insane. And is that um so you know if you're around Defcon Sunday, what time? >> Yeah, sure. Everyone is inviting, guys. And also check the video if you are not going to go. It's on Sunday in creator stage 1 10:30 a.m. So everyone is invited to sit down. >> So that means if you you know you lose your keys, um you're able to f you know get into your car anyways. Cuz if you lost your keys without and you don't have your fab, you're able to just go to this talk and you'll know how to get. >> Yeah, they're really funny because uh in my first cut I I lost my key sometimes. I I it was like, "Oh, I forget my key." But wait, I have my hack RF and I basically I use my exploit in my own car to uh get into because I forget the the key fob and after that oh the key fob was into the car and I open it and after that I came but I use my exploit to get into my car. >> Dude, I love it man. Dude, that's insane. I mean, that's a good actually util that's a good utility to have. Well, um, hey man, thanks for, uh, you know, taking me around for a cruise in this car here. Yo, FitBang, thanks for having me. >> Uh, and you know, boys, uh, if Well, I was going to say if y'all are around Sunday, go check it out. Um, thanks a lot. >> Yeah, dude. Let's do it. Let's go drink some Mezcow. Of course, >> not in the car, though.