Home / Series / Chaos Communication Congress / Aired Order / Season 39 / Episode 118

Making the Magic Leap past NVIDIA's secure bootchain and breaking some Tesla Autopilots ...

The Tegra X2 is an SoC used in devices such as the Magic Leap One, and Tesla's Autopilot 2 & 2.5 promising a secure bootchain. But how secure really is the secure boot? In this talk I go over how I went from a secured Magic Leap One headset, to exploiting the bootloader over USB, to doing fault injection to dump the BootROM, to finding and exploiting an unpatchable vulnerability in the BootROM's USB recovery mode affecting all Tegra X2s.

English
  • Originally Aired December 29, 2025
  • Runtime 60 minutes
  • Production Code 1454
  • Created December 22, 2025 by
    r4m3u5
  • Modified December 30, 2025 by
    r4m3u5