Hacking a head unit with malicious PNG

Danilo Erazo (Founder · RE Everything)

DEF CON 33 · Day 1 · Main Stage

Overview

In a compelling presentation at DEF CON, Danilo Erazo, founder of RE Everything, unveiled a significant zero-day technique targeting Kia infotainment consoles. The talk, titled "Hacking a head unit with malicious PNG," detailed a sophisticated method to compromise these in-car systems by injecting malicious PNG files into the device's firmware. This vulnerability stems from a critical oversight in the system's integrity verification process, specifically concerning the visual assets displayed on the screen.

Watch on YouTube

Visual summary for Hacking a head unit with malicious PNG by Danilo Erazo
Visual summary for Hacking a head unit with malicious PNG by Danilo Erazo

Key moments

  1. 0:00 Introduction and Kia infotainment system overview
  2. 2:00 Disassembly and hardware component identification
  3. 4:00 Firmware dumping, boot process, and UART access
  4. 5:30 Critical vulnerability: Bluetooth credentials in plaintext
  5. 6:00 Pitfalls of Binwalk for firmware reverse engineering
  6. 8:40 Discovery of 882 PNG files for all UI elements
  7. 9:40 Analysis of the Real-Time Operating System tasks

Hacking a head unit with malicious PNG

Speakers: Danilo Erazo, Founder, RE Everything

Conference: DEF CON

YouTube: https://www.youtube.com/watch?v=QKHJZ1K-7p0

Overview

In a compelling presentation at DEF CON, Danilo Erazo, founder of RE Everything, unveiled a significant zero-day technique targeting Kia infotainment consoles. The talk, titled "Hacking a head unit with malicious PNG," detailed a sophisticated method to compromise these in-car systems by injecting malicious PNG files into the device's firmware. This vulnerability stems from a critical oversight in the system's integrity verification process, specifically concerning the visual assets displayed on the screen.

Erazo's research exposes a critical gap in the automotive cybersecurity landscape: while many modern vehicles boast secure bootloaders for their core operating systems, the integrity of seemingly innocuous components like image files often remains unchecked. This oversight, as demonstrated, can be leveraged to deliver highly effective QR phishing attacks, leading to the installation of backdoor applications on users' connected smartphones. The implications are far-reaching, potentially granting attackers access to sensitive personal data, location history, and even microphone recordings, underscoring the urgent need for comprehensive security measures across all aspects of automotive software.

The presentation provided a deep dive into the hardware reverse engineering and firmware analysis required to uncover this flaw. Erazo's work highlights the importance of scrutinizing every layer of a system's security, from the system-on-a-chip (SoC) to the application-level data handling. By revealing this vulnerability, Erazo not only demonstrates a novel attack vector but also calls attention to the broader challenges of securing complex, interconnected automotive environments against evolving threats.

Background

▶ Watch: Introduction and Kia infotainment system overview (0:00)

The target of this research was a specific Kia infotainment console model, identified as the G5WB, which is prevalent in various regions outside of those using Linux or Android Automotive OS (e.g., Latin America and other unmentioned countries). Erazo noted that while newer Kia models in Australia use Linux automotive OS and those in the US, Canada, Saudi Arabia, and India use Android Automotive OS, a significant portion of the global fleet relies on an older, less transparent system. This particular head unit is supplied to Kia by Motrix, an important detail given the proprietary nature of its components.

Initial hardware analysis of the disassembled head unit revealed several key components. At its core lies an unknown system-on-a-chip (SoC), the TMM 92000, for which no public datasheet or detailed information is available. This lack of transparency immediately posed a challenge for reverse engineering. Other critical components included an older CAN microcontroller, an EPROM storing configuration data, and two flash SPI modules: a WB 25Q128 JB holding the main firmware, and another 2MB SPI flash containing a factory reset binary. The system also incorporated capacitive touch controllers, specifically the ATMXT449 and AK41 A3.

The firmware reverse engineering process was fraught with challenges. Initial attempts to analyze the binary using tools like Bingual (version 2 at the time) yielded numerous false positives, incorrectly identifying the firmware as a Q&X boot block. This necessitated a manual extraction approach, meticulously searching for known magic bytes for file types like PNG and JPEG. This manual effort led to significant discoveries, including the storage of Bluetooth data in plaintext within the firmware, exposing sensitive information like passwords and connection details. Furthermore, Erazo identified the system's Real-Time Operating System (RTOS) as IRS OS, running on an ARM Cortex A9 architecture and developed using C libraries. The firmware also contained multiple private keys and public keys, and made use of standard libraries such as libssl and libpng, both of which have historically been associated with various CVEs. These early findings highlighted a system built with several concerning security weaknesses, laying the groundwork for the discovery of the primary zero-day vulnerability.

Key Findings

▶ Watch: Firmware dumping, boot process, and UART access (4:00)

The central discovery of Danilo Erazo's research is a critical integrity verification bypass that allows for the injection of malicious PNG files into Kia infotainment console firmware. Despite the presence of a secure bootloader chain designed to protect the system's core, this protection does not extend to the graphical assets displayed on the screen.

Specifically, Erazo found that:

  • Robust Secure Boot for Core Components: The system employs a secure bootloader in the ROM, a second stage bootloader (the pre-main binary), and even performs integrity checks at the beginning of the main Real-Time Operating System (RTOS) function. This chain is designed to ensure the authenticity of the core operating system.
  • Lack of Integrity for Display Assets: Crucially, when 882 PNG files (which constitute all the images and displays seen on the head unit) are loaded from the firmware into the RAM of the system-on-a-chip (SoC), there is no integrity verification process. This creates a significant security gap, acting as a "bridge" through the otherwise secure boot chain.
  • Vulnerability Mechanism: The G_Application (the UI demo application) requests to open these PNG files. The IRS OS reads the raw PNG bytes from flash into main memory and passes them to the libpng library. While libpng performs internal checks (like CRC verification for its internal chunks and header parsing), these checks are insufficient to detect a malicious image if its overall hash or digital signature is not independently verified by the system. As long as the malicious PNG maintains the same size and valid PNG metadata as the original, it will be loaded and rendered without issue.
  • Sophisticated Phishing Vector: This vulnerability can be exploited to replace legitimate images, such as QR codes, with malicious ones. The demonstration showed how a modified QR code could redirect users to a phishing website, which then prompts the download of a backdoor-infected Android application. This effectively turns the vehicle's trusted display into a launchpad for Command and Control (C2) attacks against connected smartphones, granting attackers access to sensitive data like location, contacts, SMS, and even microphone recordings.

This finding underscores a critical security principle: the chain of trust must extend to all loaded assets, not just the operating system kernel. The "malicious PNG" technique highlights how overlooked components can become powerful entry points for sophisticated attacks.

Technical Deep Dive

▶ Watch: Critical vulnerability: Bluetooth credentials in plaintext (5:30)

Danilo Erazo's investigation began with extensive hardware reverse engineering of the Kia infotainment console. The head unit contained an undocumented TMM 92000 system-on-a-chip (SoC), an older CAN microcontroller, and several memory components. The EPROM stores configuration data and communicates via I2C, while the main firmware resides on a flash SPI (WB 25Q128 JB) that communicates via SPI. A crucial breakthrough was identifying UART access on the backside of the unit, which proved invaluable for debugging and observing boot process logs.

The firmware analysis involved overcoming significant hurdles. Initial attempts with tools like Bingual (version 2) incorrectly identified the firmware as a Q&X boot block due to a misinterpretation of magic bytes (specifically EV 1090, which Bingual erroneously associated with Q&X, but Erazo identified as part of a branch link exchange instruction in the ARM Thumb architecture, Big Endian format). This led to hundreds of false positives and a necessity for manual extraction of embedded files. Through this meticulous process, Erazo uncovered the firmware's structure:

  • A RAR file for recovery/factory reset.
  • A large RAR file for pre-main, which serves as the second stage bootloader.
  • Another RAR file containing the kernel, file system, certificates, private keys, public keys, and embedded PNG files.
  • A section with firmware and software information.
  • Alarmingly, Bluetooth data in plaintext, including passwords and connection details.
  • A total of 882 PNG files were identified, comprising all the graphical elements displayed by the head unit.

The boot process was meticulously mapped. The system starts with a root bootloader (in ROM), which then loads the second stage bootloader (pre-main binary) from the flash SPI. This pre-main binary subsequently loads the main Real-Time Operating System (RTOS), identified as IRS OS, developed in C libraries for an ARM Cortex A9 processor. Crucially, Erazo confirmed that integrity checks are performed at the ROM boot stage, for the second stage bootloader, and at the entry point of the main IRS OS function. However, a glaring omission was found in the loading of the PNG files.

The vulnerability specifically lies in how these 882 PNG files are handled. When the G_Application (the UI demo component) requires an image, it issues a file_open call to the IRS OS. The operating system reads the raw PNG bytes from the flash SPI into main memory via the system's memory controller and bus fabric. These bytes are then passed to the libpng library for parsing. While libpng performs internal checksum verification for its chunks and decompresses the image into an RGBA buffer, it does not verify the overall integrity of the image against a trusted cryptographic hash or signature. Erazo demonstrated this by compressing a modified pre-main binary with "version form" RAR compression and patching the firmware; the system failed to boot, showing a white image, confirming the integrity check for the bootloader. However, when a PNG was similarly modified, the system booted normally and displayed the altered image. This confirms that while the core system is protected, the visual assets are not, creating a critical attack surface.

The requirements for a successful malicious PNG injection are precise: the fake image must be the exact same size as the original, and it must contain valid PNG headers and metadata that satisfy libpng's internal checks. If the image is smaller, padding with zeros is an option, but the image will not render if compressed. The goal is to replace an image at its original offset in the firmware, ensuring the system loads the malicious content seamlessly.

Demo / Proof of Concept

▶ Watch: Discovery of 882 PNG files for all UI elements (8:40)

Danilo Erazo's demonstration vividly illustrated the severity of the malicious PNG vulnerability. The initial proof of concept involved a straightforward image replacement. Erazo modified a Kia logo embedded in the firmware, replacing it with the word "HACK." Upon reflashing the head unit with this modified firmware, the system booted normally, and the altered image was displayed on the screen. This "hello world" test confirmed that the boot process did not detect the unauthorized change in the PNG file, validating the lack of integrity verification.

Building on this, Erazo presented a more sophisticated and dangerous attack scenario: a QR phishing scheme. He identified a legitimate QR code image within the head unit's interface, specifically one found in the "setup system and manual" section, which typically redirects users to the official Kia user manual online. Using Inkscape (INSK), a graphic design tool, Erazo crafted a malicious PNG that precisely matched the dimensions, pixel count, and all necessary PNG metadata of the original QR code. This new QR code, when scanned, would redirect to a phishing webpage controlled by the attacker (revisit.com).

The demonstration proceeded as follows:

  1. Firmware Patching: The malicious PNG (containing the attacker's QR code) was injected into the vehicle's firmware, replacing the original QR code image.
  2. Head Unit Compromise: The head unit was then flashed with this modified firmware (requiring either USB access or direct hardware hacking for flashing).
  3. QR Code Scan: Erazo simulated a user scanning the QR code displayed on the compromised head unit. Instead of navigating to the official Kia manual, the user's phone was redirected to revisit.com.
  4. Phishing Site: The phishing webpage, designed to mimic Kia's official branding, presented a "Download Kia official app" button.
  5. Malware Delivery: Clicking this button initiated the download of a malware application – an official Kia Android app that had been backdoor-infected. Erazo noted that this malicious APK had Android detection bypass capabilities, meaning it would likely evade typical mobile antivirus scans.
  6. Metasploit Session: Upon installing and opening the infected app on an Android 14 test phone, Erazo immediately gained a Metasploit Meterpreter session on the phone. From his Command and Control (C2) server, he demonstrated full access to the device, executing commands like sysinfo, getuid, dump_sms, and confirming the ability to access location, contacts, and even record the microphone.

This comprehensive demo showcased a complete attack chain, transforming a seemingly benign image file vulnerability in a car's infotainment console into a potent tool for compromising personal mobile devices and exfiltrating highly sensitive user data. Erazo emphasized the zero-day nature of this vulnerability, stating that Kia had not yet patched it.

Defensive Implications

▶ Watch: Analysis of the Real-Time Operating System tasks (9:40)

The "Hacking a head unit with malicious PNG" talk by Danilo Erazo highlights several critical areas where automotive manufacturers and security defenders must focus their efforts to enhance vehicle cybersecurity:

  1. Comprehensive Integrity Verification: The most immediate and crucial defensive implication is the need for robust integrity checks on all assets loaded from firmware, not just the core Real-Time Operating System (RTOS) or bootloaders. This includes graphical assets like PNG files, fonts, and other display elements. Cryptographic hashing (e.g., SHA-256) or digital signatures should be implemented for every resource, with verification occurring prior to loading into RAM.
  2. Extend Secure Boot Chain: The concept of secure boot must be expanded to encompass the entire operational stack. While the root bootloader and second stage bootloader may be secured, the demonstrated vulnerability shows that a gap in the trust chain for application-level resources can completely undermine these protections.
  3. Regular and Timely Firmware Updates: OEMs like Kia must establish efficient and reliable mechanisms for delivering firmware updates to address discovered vulnerabilities promptly. As this was presented as a zero-day technique, a rapid response is essential to protect existing vehicles.
  4. Secure Handling of Sensitive Data: The discovery of Bluetooth data in plaintext within the firmware is a severe security flaw. All sensitive configuration data, credentials, and user information must be encrypted and stored securely, preferably in hardware-backed secure storage.
  5. Supply Chain Security and Third-Party Components: The reliance on an unknown SoC (TMM 92000) and third-party libraries like libpng and libssl necessitates rigorous security audits. OEMs must demand comprehensive security documentation, source code reviews, and vulnerability assessments from their suppliers. Any identified CVEs in these libraries must be patched immediately.
  6. User Awareness and Education: While technical solutions are paramount, educating users about the dangers of QR phishing and the risks associated with downloading unofficial applications is also important. However, the sophistication of this attack, leveraging a trusted vehicle display, makes user education alone insufficient.
  7. Threat Modeling and Attack Surface Analysis: Manufacturers need to conduct thorough threat modeling exercises that consider non-traditional attack vectors, such as the manipulation of visual assets. The infotainment console is a high-interaction point for users and thus represents a significant attack surface that requires constant scrutiny.
  8. Automated Security Testing: Implementing automated tools for firmware analysis and vulnerability detection can help identify similar weaknesses across other models and systems. While Bingual initially provided false positives, continuous improvement of such tools and manual verification remain critical.

In essence, defenders must adopt a holistic security approach, ensuring that every piece of software and data, from the lowest-level hardware to the highest-level user interface elements, is protected by a strong and unbroken chain of trust.

Key Takeaways

  • Zero-Day Vulnerability: Kia infotainment consoles (specific models, e.g., G5WB) are susceptible to a zero-day technique involving the injection of malicious PNG files into the firmware.
  • Integrity Verification Gap: Despite a secure bootloader chain protecting the core Real-Time Operating System (RTOS), there is a critical lack of integrity verification for the 882 PNG files that constitute the vehicle's display assets.
  • Sophisticated Phishing Vector: Attackers can replace legitimate images, such as QR codes, with malicious ones. This enables highly effective QR phishing attacks that redirect users to attacker-controlled sites.
  • Smartphone Compromise: The phishing attack can lead to the download and installation of backdoor-infected Android applications on connected smartphones, granting attackers full access to sensitive data like location, contacts, SMS, and microphone recordings (demonstrated with Metasploit Meterpreter).
  • Hardware Access Required: The current method of exploitation requires physical access to the head unit for hardware hacking (e.g., USB flashing) to install the modified firmware.
  • Fundamental Security Flaws: Beyond the PNG vulnerability, the system exhibits other weaknesses, including the storage of Bluetooth data in plaintext and the use of an undocumented TMM 92000 SoC, highlighting broader security concerns in the vehicle's architecture.

About the Speaker(s)

Danilo Erazo is a prominent figure in the cybersecurity community, particularly recognized for his contributions to hardware security and car hacking. He is the founder of RE Everything, a company specializing in secure pentesting services. Erazo is also the founder of Power Die, an "underground" security conference held in Ecuador, and the founder of the Car Hacking Village at CopaRI in Buenos Aires, one of Latin America's largest security conferences. With a passion for hardware security in his free time, Danilo Erazo actively shares his research and knowledge, including through his YouTube channel. His work consistently pushes the boundaries of understanding and securing complex embedded systems, as evidenced by his detailed analysis of the Kia infotainment console.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

Solid automotive embedded security research with a real zero-day, genuine hardware teardown, and a complete end-to-end attack chain demo. The vulnerability itself — missing integrity verification on PNG assets despite a nominally secure boot chain — is a clean, well-scoped finding that makes a point the industry keeps ignoring. Not a world-ender, but it's real work on a real target with receipts.

Heather Calloway (CISO) — WEAK

Technically credible hardware research with a real finding — an unverified asset class in an otherwise signed firmware chain — but the talk never crosses into territory that matters to defenders, OEM security teams, or automotive governance. The attack requires physical access to flash the device, which is buried in the fine print, and the QR phishing payload is a smartphone problem dressed up as a vehicle security problem.

→ Top-rated talks at DEF CON 33

All talks from DEF CON 33