Video summary
The video takes place inside a 2025 electric Volkswagen bus at DEF CON 34, where security researchers discuss various attack vectors targeting modern vehicles. The primary entry points identified include USB ports and Bluetooth stacks, which often contain proprietary vulnerabilities that can be exploited without user interaction or authentication. By connecting an infected device via these interfaces, attackers could gain direct access to the infotainment system, allowing them to perform lateral movement across other electronic control units within the car. This level of compromise enables malicious actors to unlock doors, start or stop the engine, and even record audio from interior microphones, effectively turning a connected feature into a critical security weakness.
A particularly alarming example highlighted involves a low-energy Bluetooth device installed in many California vehicles intended to enhance security but which ironically created new vulnerabilities. Researchers demonstrated that within a range of approximately 20 meters, an attacker could exploit memory corruption flaws in the proprietary stack to hack cars without needing any credentials or physical access. Although patches have since been released for this specific issue, the incident revealed how widespread the vulnerability was before mitigation, affecting up to ninety percent of affected vehicles and proving that security-focused hardware can sometimes introduce significant risks if not rigorously tested against real-world attack scenarios like man-in-the-middle attacks on EV charger communication protocols.
The discussion further explores advanced techniques such as brute-forcing rolling code systems designed to prevent replay attacks in keyless entry mechanisms. By analyzing the frequency frames sent between the fob and the vehicle, attackers can potentially bypass these countermeasures entirely, effectively neutralizing the protection offered by modern anti-replay technologies. This capability means that even with sophisticated security features like rolling codes, a determined adversary could duplicate keys or unlock vehicles remotely without possessing the physical key fob. The researchers emphasize that such exploits are not just theoretical but have been successfully tested on very recent models from 2025 and potentially future years like 2026, underscoring the urgent need for continuous security updates in automotive software ecosystems.
In conclusion, the session serves as a stark reminder of the evolving landscape of car hacking where convenience features often expand the attack surface rather than reduce it. The ability to access critical vehicle functions through seemingly benign connections like Bluetooth or USB ports illustrates why manufacturers must prioritize secure coding practices and transparent vulnerability disclosure over proprietary obfuscation that hinders independent security audits. As vehicles become increasingly interconnected with external networks, ensuring robust defenses against zero-click exploits becomes essential for protecting both consumer privacy and physical safety on the road.
Read the full video transcript
We are in the car hacking village. I am
here with Reverse Everything and
Bitbang. We are inside of a VW bus uh
2025 electric. Right, tell us a little
bit about the exploits of what we're
looking at here. We're going to talk
about some vector points of things that
you would want to hit and other
exploits.
>> Sure. Nice to meet you guys. So here we
have a lot of attack vectors in nowadays
the car have a lot of attack vectors.
Here we have a USBC port right here we
have in this car three USBC ports and
this is an attack vectors for malicious
actors because h there could be like in
the USB stacks probably should be uh
vulnerabilities right and also another
attack vector that is very exploited it
is the Bluetooth right in the most of
the cases the Bluetooth stack is
proprietary that's the reason that the
the attack that attackers hack this the
another attack vector as well and the
people don't know about that is about
the radio frequency and the radio
frequency is like the key fob, the TPMS,
you know, the tire precious monitor
system and also about the telematic
control unit that is connected to a
basis station is also another type
vector frequency as well. So h there are
more and right now in this car this is
like a post bagging ID bus we have a EV
charger and right now is like very
popular this kind of res in the EV
charger because this PLC communication
that when you connect it's not just
voltage it's not just current it's
frames travel between the station and
the car and this is very dangerous
because maybe there is like man in the
middle attacks and this kind of things
so has a very quite interesting problem.
For example, some CVEs that are found in
the Bluetooth proprietary sts about h
memory corruption. So for example h if I
connect my phone and I have this
basically I can get access to the
infotainment system. I can get access a
reshelf h with a zero click or one
click. When I mention zero click is
without authentication, without touching
the screen, without touching the screen
the and even worse without touching the
the without touching things is like a
zero click, right? And yeah, this is
like this kind of exploits that
literally you get access to the car and
after that you can do lateral movement
to the another electronic control unit
and you can unlock the car, stop the
car, power on the motor, kill the motor
>> through infotainment
>> through the infotainment system. Yeah.
Yeah. Yeah. It's like the the main part.
>> Got it. That's pretty serious. We're
we're sitting in traffic, right? Um I
have the Bluetooth on pairing. Um, is
there potential like you could be
sitting in a car next to this car and
run an attack?
>> Yeah, that's very good because and
that's a very good point because
honestly like one more appear something
in San in California appears there's
like a in the California the cars by
default sell you with a device that
allow you to protect your car and this
device is connected to all the canvas.
It's is it's this like uh it's not a
mandatory but you can say hey I don't
want that but if you don't say that it
doesn't really matter because this
device is already installed they
disabled that and this new was very cool
because this art just appeared one ago
or maybe three weeks ago because this is
through Bluetooth right and there is
like a guy there's a documental invite
to to see this there's a documental that
there's like a guide with a car looking
for how many cars have this device
through Bluetooth. So they discovered
this through Bluetooth. They discovered
using approach like around maybe 20 m uh
they was able to hack a car in a radio
of 20 m. So he was driving a car with
this sniffing what are the cars that
have this vulnerable device and right
now in California there are many many
cars that have this. The update is
already exist. The the update the patch
already exist. But one more ago anyone
absolutely anyone without a without
authentication without knowing just the
was necessary to stay like 20 m 10 m you
know in the to low energy range and he
was able to to to hack the car, unlock
the car, start the car, record car, the
microphone, everything. Everything.
>> Dang. That vulnerability was just
patched like a month ago. So that was
>> Yeah. So there was a new in California
all the maybe the 90% of the cars was
vulnerable to this. And this is insane
because this device was created for do
security in the car but this is security
create insecurity.
>> It was the vulnerability itself.
>> Yeah. Yeah.
>> That's crazy. Which leads me to so I
know you are doing a talk on Sunday um
how to get into cars without the key
fob. Correct.
>> Yeah, sure.
>> Talk to me, man. What do we got? What
are you going to be really bringing up
with that vulnerability?
>> Yeah, I'm I'm pretty excited about that
because we are going to do like a brute
force to the rolling code. Rolling code
is the um security system that allow you
to protect your car in order to avoid a
replay and in the middle attack. So,
each time you press the button, you have
a different con that going to unlock the
car. But what happen if I discover the
way to communicate and the way to with
the frame and send the frame to write a
frequency and do the brute force attack
to the counter or to the random part
basically and if we mix this with
another vulnerability h basically we can
duplicate the key fob and after that
unlock the car without the key fob or
even in 2026 car 2025 cars
>> that's even with like a rolling code
that you you're able to still
>> Yeah exactly it's like hug the rolling
code like completely
completely kill the rolling code.
>> That's that's insane. And is that um so
you know if you're around Defcon Sunday,
what time?
>> Yeah, sure. Everyone is inviting, guys.
And also check the video if you are not
going to go. It's on Sunday in creator
stage 1 10:30 a.m. So everyone is
invited to sit down.
>> So that means if you you know you lose
your keys, um you're able to f you know
get into your car anyways. Cuz if you
lost your keys without and you don't
have your fab, you're able to just go to
this talk and you'll know how to get.
>> Yeah, they're really funny because uh in
my first cut I I lost my key sometimes.
I I it was like, "Oh, I forget my key."
But wait, I have my hack RF and I
basically I use my exploit in my own car
to uh get into because I forget the the
key fob and after that oh the key fob
was into the car and I open it and after
that I came but I use my exploit to get
into my car.
>> Dude, I love it man. Dude, that's
insane. I mean, that's a good actually
util that's a good utility to have.
Well, um, hey man, thanks for, uh, you
know, taking me around for a cruise in
this car here. Yo, FitBang, thanks for
having me.
>> Uh, and you know, boys, uh, if Well, I
was going to say if y'all are around
Sunday, go check it out. Um, thanks a
lot.
>> Yeah, dude. Let's do it. Let's go drink
some Mezcow. Of course,
>> not in the car, though.