Researchers at Télécom SudParis reported that modern vehicle software platforms inherit large numbers of publicly documented vulnerabilities from upstream technologies including Linux, Android, QNX, and VxWorks, exposing weaknesses deep inside infotainment and automotive operating system stacks. Using a purpose-built scanner called VERA, the team analyzed automotive software images and found wide variation across platforms, including 1,203 documented vulnerabilities in the tested version of Automotive Grade Linux, while safety-certified systems such as QNX Neutrino and VxWorks 7 still contained dozens of known flaws listed in public vulnerability databases such as CVE and the EUVD.
The researchers said raw vulnerability totals do not automatically equate to practical compromise because exploitability depends on whether affected components are enabled, reachable, and shielded by platform-specific defenses. To test real-world impact, they developed two proof-of-concept attacks: one targeting SQLite on Android Automotive and another targeting SOME/IP communications, with the SOME/IP attack succeeding against Red Hat AutoSD and Tesla software but failing on Android Automotive. The study also found that general-purpose scanners such as Trivy generated many false positives in automotive environments, prompting the team to use VERA to produce a more actionable view of vehicle software risk.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Help Net Security reported that Télécom SudParis researchers analyzed modern vehicle software stacks and found inherited vulnerabilities from Linux, Android, QNX, and VxWorks. The study introduced the VERA scanner and described proof-of-concept attacks against SQLite on Android Automotive and SOME/IP, with the SOME/IP attack succeeding on Red Hat AutoSD and Tesla software but failing on Android Automotive.
A CVE reference associated with this story was published on CVE.org. The provided content does not include technical details from the CVE entry itself.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcecve.org
Open sourcehakstuff.net
Open sourceeuvd.enisa.europa.eu
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.