Teenager Takes Control of 25+ Teslas: It’s probably nothing to worry about…

So, I now have full remote control of over 20 Tesla’s in 10 countries and there seems to be no way to find the owners and report it to them…

Since these important facts seem to drown between other comments, I‘ll add them here again 👇

This is not a vulnerability in Tesla‘s infrastructure. It‘s the owners faults. That‘s why I would need to report this to the owners as stated above.

Nevertheless I now can remotely run commands on 25+ Tesla‘s in 13 countries without the owners knowledge.

Regarding what I‘m able to do with these Tesla‘s now.
This includes disabling Sentry Mode, opening the doors/windows and even starting Keyless Driving.

I could also query the exact location, see if a driver is present and so on. The list is pretty long.

And yes, I also could remotely rickroll the affected owners by playing Rick Astley on Youtube in their Tesla‘s😂

I think it‘s pretty dangerous if someone is able to remotely blast music on full volume or open the windows/doors while you are on the highway.

Even flashing the lights non-stop can potentially have some (dangerous) impact on other drivers.

That‘s why I would like to get this all fixed before I release any specific details regarding what exactly this all is about.

Next steps:
– Waiting for MITRE‘s reply regarding a CVE
– Preparing my Writeup
– Coordinating disclosure to affected owners with Tesla

Small addition (for media reporters):

As already stated in some other replies, it is not “full remote control” as in being able to remotely control steering or acceleration & braking.

Yes, I potentially could unlock the doors and start driving the affected Tesla‘s.

No I can not intervene with someone driving (other than starting music at max volume or flashing lights) and I also can not drive these Tesla‘s remotely.

Addition as of 11. Jan 22:33 (CET)

Tesla‘s Security Team just confirmed to me they’re investigating and will get back to me with updates as soon as they have them.

The MITRE CVE Assignment Team reserved a CVE for it.

  • KCK January 14, 2022, 8:15 AM

    Put this down as one more reason I will never love the coal powered car.

  • gwbnyc January 14, 2022, 8:22 AM

    I haven’t owned a car for decades. I’ll buy one this year and it’s going to be a Super Beetle.

  • Richard January 14, 2022, 8:26 AM

    Just one more reason, among many, that I hope to hold onto my “dumb” 2001 Accord until I can no longer drive.

  • Mike Austin January 14, 2022, 8:31 AM

    All vehicles since 2015 or earlier can be hacked. That is, somebody, some government agency or some rando high-IQ computer geek can remotely—and this is the key: remotely—take control over your vehicle. This was probably behind the death—the “cyber-assassination”—of Michael Hastings.

    “Richard Clarke, the counterterrorism chief under both Bill Clinton and George W. Bush, told the Huffington Post that Hastings’s crash looked “consistent with a car cyber attack….What did he mean? According to Stefan Savage, a computer science professor at the University of California, San Diego, any modern vehicle’s computer system made by any manufacturer can be hacked.”

    See this video. All is explained.


    Think about this the next time you get into your car. I have no car, only bicycles. You cannot hack a machine that runs on muscle rather than fancy code and computer chips.

  • Dirk January 14, 2022, 9:03 AM

    • John Venlet January 15, 2022, 8:12 AM

  • Anonymous January 14, 2022, 10:33 AM

