πΉπππππ π¬πππππππππππ ππ π΅πππππ π³πππ: πͺππππππππππ πͺπππππππ π©ππ
π π¬πππππππ ππππ πππ π°πππππππ
π Electric cars arenβt silent to hackers!
At Black Hat Asia 2025 the PCA Cyber Security crew showed how 30 seconds of Bluetooth proximity is enough to jump from the infotainment system to full vehicle control of a 2020 Nissan Leaf.
πΆ Attack chain in a nutshell β
Bluetooth HFP buffer-overflow (CVE-2025-32059) β root on BlueDragon Evo β Secure-Boot bypass β covert DNS C2 over cellular β CAN-gateway filter evasion β doors, mirrors, wipers β¦ even steering at highway speed!
π₯ Why it matters
The research proves that βinfotainment β harmlessβ β once inside, attackers can eavesdrop on in-cabin audio, track GPS, and physically move the car from anywhere on the Internet. Nissan issued firmware fixes after coordinated disclosure. Update now! π‘οΈ
π§ Key takeaways for defenders
β’Harden third-party Bluetooth stacks & eliminate fixed library load addresses.
β’Physically isolate safety-critical CAN traffic from consumer networks.
β’Treat every pairing request like a potential drive-by exploit.
#AutomotiveSecurity #BluetoothHacking #CarHacking #CANBus #RemoteExploitation #Infosec #EmbeddedSecurity
π₯ Demo video:
youtube.com/watch?v=56VreoKtβ¦
π Slides (PDF):
i.blackhat.com/Asia-25/Asia-β¦
πΉπππ ππππ π‘π π βπππ π‘βππ π€ππ‘β π¦ππ’π ππππππππ’ππ ! π΄ππ ππππππππβ¦ ππ‘ππ¦ ππππ πππ π»πππ π
ππ ππππ ππππ¦! ππ΄ββ οΈ