Millions of California-bought cars can be hijacked via Bluetooth

Summary

Researchers at UC San Diego have discovered a vulnerability in aftermarket KARR/SWDS security systems commonly installed in cars sold in California. The systems share a common, insecure Bluetooth key, allowing attackers to remotely unlock and potentially hijack vehicles equipped with them.

IFF Assessment

FOE

This vulnerability allows for the remote hijacking of vehicles, posing a significant threat to car owners and potentially enabling further criminal activity.

Severity

8.0 High (AI Estimated)

The vulnerability allows for remote code execution and physical access to the vehicle, with a high attack vector and significant impact on confidentiality, integrity, and availability.

Defender Context

This highlights the risk of relying on third-party, aftermarket security systems that may not undergo rigorous security testing. Defenders should be aware of such vulnerabilities in automotive systems and advise users to check for potential exploits or consider disabling non-essential Bluetooth features on vehicle security systems.

Read Full Story →