Drone-Hacking Tesla Model X: How the TBONE Zero-Click Exploit Worked

13

Security researchers didn’t just break into a Tesla. They flew a drone to do it.

During the Pwn2Own contest at CanSecWest in Vancouver, Germany-based experts Ralf-Philipp Weinmann and Benedikt Schmotzle staged a remote intrusion that felt like something out of a spy thriller. They used a consumer-grade DJI Mavic 2 drone paired with a standard Wi-Fi dongle. The target? A Tesla Model X.

The result was a full remote access demonstration. It took less than three minutes. They unlocked the doors. Opened them. And in doing so, exposed a critical vulnerability in the automotive industry’s reliance on open-source networking software.

The TBONE Attack Vector

The exploit, dubbed TBONE, targets the infotainment system found in Tesla’s Model S, 3, X, and Y vehicles. But the flaw isn’t unique to Tesla. It lies within ConnMan, an open-source connection manager used by several automakers to handle internet connectivity.

Weinmann and Schmotzle exploited two specific security flaws within ConnMan. This allowed them to execute a zero-click attack. No interaction from the car owner was needed. No phishing email. No physical access to the vehicle.

The drone acted as a mobile command station. Operating from a distance of up to 100 meters, the attackers connected to the car’s Wi-Fi network. Once inside, the scope of control was extensive.

The researchers could unlock doors and the trunk. Adjust seat positions. Modify steering and acceleration settings.

It wasn’t just about opening doors. The exploit allowed them to change fundamental vehicle configurations. They noted that with additional hardware, they could even inject new Wi-Fi firmware. This would turn the compromised Tesla into an access point, potentially allowing them to pivot and hack other nearby Teslas.

Why This Matters for Connected Cars

The TBONE attack highlights a dangerous trend: automakers are integrating complex, open-source software into critical vehicle systems without rigorous security auditing. ConnMan is designed for convenience, not defense. When that software handles the bridge between a car and the internet, the attack surface expands exponentially.

The researchers demonstrated that physical proximity isn’t the only risk factor. A drone can bypass the “lockdown” of a parked car, leveraging the vehicle’s own connectivity features against it. While the exploit doesn’t allow for full autonomous control—meaning they couldn’t steer the car off a cliff remotely—it grants enough access to cause significant disruption or prepare for deeper, more dangerous intrusions.

Tesla’s Response and Industry Gap

Tesla didn’t wait for a public disclosure to act. The researchers had previously notified Tesla, Intel (the original creator of ConnMan), and the German CERT. They also alerted other manufacturers who might be using the same underlying technology.

Tesla pushed a software update in October to patch the vulnerability. They also awarded Weinmann and Schmotzle a bug bounty of $31,500. This is a standard practice in responsible disclosure, but it raises uncomfortable questions about the rest of the industry.

Other automakers using ConnMan have not been as transparent. We don’t know if they’ve released similar fixes. We don’t know if their customers are equally exposed to zero-click exploits via Wi-Fi-connected drones.

The tech is out there. The drone is affordable. The flaw is real. Until the entire industry updates its firmware, your car might be more connected than you think. And sometimes, connection means an open door.