BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//pretalx.com//hack-lu-2025//talk//LPVDSH
BEGIN:VTIMEZONE
TZID:CET
BEGIN:STANDARD
DTSTART:20001029T040000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000326T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=3
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-hack-lu-2025-LPVDSH@pretalx.com
DTSTART;TZID=CET:20251024T090000
DTEND;TZID=CET:20251024T093000
DESCRIPTION:In this presentation\, we share the methodology used during a s
 ecurity audit of the Carplay application. This application exposes service
 s to external car interfaces through Bluetooth and Wi-Fi. **Our work focus
 ed on identifying vulnerabilities that could lead to compromise the multim
 edia equipment\, by an attacker already connected to the car's Wi-Fi hotsp
 ot.** \n\nDuring this analysis\, we present how we identified the function
  responsible for parsing external data sent to the car\, how we fuzzed it 
 and discovered a bug already known by Apple (CVE 2023-23494).
DTSTAMP:20260713T193042Z
LOCATION:Europe
SUMMARY:Audit and retrospective of an automotive application: Carplay - Eti
 enne CHARRON\, Khadim
URL:https://pretalx.com/hack-lu-2025/talk/LPVDSH/
END:VEVENT
END:VCALENDAR
