DEF CON 33 - Hacking a head unit with malicious PNG - Danilo Erazo

DEF CON 33 - Hacking a head unit with malicious PNG - Danilo Erazo

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 23:52

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

The video reveals a zero-day vulnerability in Kia infotainment systems allowing attackers to inject malicious PNG files during boot, leading to full device compromise and remote access to Android phone data. 1:50

Key Takeaways:
• A critical vulnerability exists in the PNG image loading process where no integrity verification occurs, enabling arbitrary image replacement 17:23-17:38.
• Attackers can replace any image in the firmware with a malicious one of identical size and metadata, bypassing PNG library checks 18:41-19:04.
• A fully functional phishing attack was demonstrated using a fake Kia app that redirects to a malicious webpage and installs malware with backdoor access to the Android phone 20:57-23:25.
• The attack exploits the lack of cryptographic validation in the boot process, allowing unauthorized access to phone data including SMS, location, and microphone recordings 23:00-23:25.

This zero-day exploit enables full remote control of the vehicle’s infotainment system and access to sensitive personal data, highlighting severe security flaws in automotive software. 23:36

Sources:

  • 1:50 Discussion of the zero-day vulnerability in Kia infotainment systems.
  • 17:23-17:38 Explanation of the missing integrity check in PNG image loading.
  • 18:41-19:04 Description of how malicious PNGs are injected and rendered.
  • 20:57-23:25 Demonstration of the phishing attack and app installation.
  • 23:00-23:25(h

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Okay and good afternoon every hacker for me is a pleasure to stay here for a second time in the car hacking village so yeah let's go ahead hacking a unit with a malicious PNG this is a zero day technique it's I hope you enjoy okay who I'm very fast I'm the founder of re everything a company that I guess secure pentesting the founder of the power die the most underground conference in all over the world is in Ecuador uh you are invited is very andro. I really like it. The founder of the car hacking villas of the copari also you're invited in Buenosiris the most important biggest Latin American conference. I am hardware security in my free time s and you my YouTube channel if you scan the QR. So uh we are talking about the Kia infotainment console. Okay. So in this case we have that Kia Kia …