Discovered by researchers from Synacktiv at Pwn2Own Vancouver 2024, the flaw enabled unauthorized control over critical vehicle functions without user interaction.
The exploit targets the Vehicle Controller Secondary (VCSEC) module, which manages TPMS communications, door locks, and startup procedures.
Attackers could manipulate the certificate authentication process during TPMS sensor pairing, triggering an integer overflow in the VCSEC’s memory.
This flaw allowed malicious code execution, potentially enabling attackers to send arbitrary commands to the vehicle’s Controller Area Network (CAN) bus-a system governing functions like acceleration and braking.
Key technical factors include:
Impact and Remediation
Successful exploitation could lead to vehicle theft, unauthorized access, or disruption of safety-critical systems. Tesla addressed the issue in Firmware Version 2024.14, released in April 2025.
The vulnerability scored a CVSS 7.5 (High severity), with risks mitigated by its network-adjacent attack requirement.
Security experts emphasize the growing importance of securing automotive systems, particularly as vehicles adopt more wireless interfaces.
Synacktiv researchers Thomas Imbert, Vincent Dehors, and David Berard were credited with the discovery.
This incident underscores the challenges in securing complex vehicle ecosystems, where a single component-like the TPMS-can serve as a gateway for broader system compromise.
Tesla’s rapid response highlights the auto industry’s increasing reliance on coordinated vulnerability disclosure programs to address emerging threats.
Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant updates
The post Tesla Model 3 VCSEC Flaw Enables Remote Code Execution by Attackers appeared first on Cyber Security News.
Between the ubiquitous virtual assistants cheerfully patronising us from almost every electronic device and the…
If you're a Windows user who's looking for a PC version of the Apple Mac…
FORT WAYNE, Ind. (WOWO) — The state of Indiana has agreed to let the Indiana…
FORT WAYNE, Ind. (WOWO) — Severe thunderstorms are expected to move across central Indiana in…
Universal Pictures and Focus Features have taken the stage at CinemaCon. We're expecting new looks…
Maritza Montejo, a Liberty Tax Service office manager, helps Aurora Hernandez, left, with her taxes…
This website uses cookies.