Photo of Tesla Car Interior Showing Media Display
© Carrie Fereday/Shutterstock.com
No AI-generated content: this article is written and researched by humans
Table of contents

Researchers have figured out a way to exploit a vulnerability in the AMD-based infotainment system used in newer Telsa cars to run any software and access premium features.

The exploit, which is “unpatchable,” also allows unauthorized parties to access the unique hardware-bound RSA key on Tesla vehicles.

The three researchers from the Technical University of Berlin (TU Berlin) — Ph.D. students Christian Werling, Niclas Kühnapfel, and Hans Niklas Jacob — together with independent security researcher Oleg Drokin will be presenting at BlackHat 2023 on Wednesday, August 9.

An announcement on the BlackHat website says the researchers “will present an attack against newer AMD-based infotainment systems (MCU-Z) used on all recent [Tesla] models.”

Tesla Jailbreak

The “unpatchable” exploit in Tesla’s AMD processor-based Media Control Unit (MCU) allowed the researchers to permanently activate premium features, such as the heated steering wheel, footwell lights, and “Acceleration Boost.”

“For this, we are using a known voltage fault injection attack against the AMD Secure Processor (ASP), serving as the root of trust for the system,” the researchers said.

Besides exposing the RSA key on Tesla cars, the exploit could also expose personal user data like phonebook, calendar entries, passwords, and more.

On a positive note, the jailbreak could allow people to use Tesla cars in unsupported regions, the researchers said.

“Furthermore, the ASP attack opens up the possibility of extracting a TPM-protected attestation key Tesla uses to authenticate the car. This enables migrating a car’s identity to another car computer without Tesla’s help whatsoever, easing certain repairing efforts,” they added.

This discovery mirrors similar findings in a whitepaper published in August 2021 by a different group of researchers at TU Berlin. The 2021 paper explored the use of voltage fault injection attacks against the AMD Secure Processor (ASP) and how it can survive reboots and updates.

Tesla Faces a Unique Challenge

The announcement of this presentation at BlackHat 2023 has drawn attention to a significant dilemma for Tesla. Traditional fixes like software patches are ineffective against this particular exploit, leaving the EV automaker in uncharted territory.

Tesla could replace the affected MCU hardware with a processor that’s resistant to fault injection attacks, Jacob told VPNOverview. However, the logistics and costs of such a measure are unclear at this time. On the other hand, AMD may also need to consider adding fault injection “countermeasure into their next CPU generation,” he noted.

With the anticipation building toward the BlackHat 2023 event, the automotive sector, cybersecurity experts, and Tesla owners are keen to hear the full details of this “unpatchable” hack.

We recommend Tesla owners keep their cars updated with the latest software at all times.

One Glitch to Rule Them All: Fault Injection Attacks Against the AMD Secure Processor

Follow us on Twitter, Threads, and Mastodon for more EV-related cybersecurity news!

Leave a comment