Attack on Subaru Software
|

Attack on Subaru Software

Spread the love
MY20 CTK Front Seat Perspective Couple Driving in Woods
Attack on Subaru Software 5

Vulnerability Found in Subaru Software, Allowing Remote Unlocking, Starting, and Tracking of Millions of Vehicles

Cybersecurity researchers Sam Curry and Shubham Shah uncovered vulnerabilities in Subaru’s Starlink infotainment system (unrelated to SpaceX’s satellite service) that enabled partial remote control of vehicles and tracking of their movements.

The researchers managed to exploit the Starlink system through Subaru’s web portal. By replicating their actions, a potential attacker could unlock the car, honk the horn, start the engine, and even assign these functions to another phone or computer. Additionally, the system allowed for tracking the current location of a Subaru vehicle and viewing its movement history.

In one example, Curry used his mother’s car to test the vulnerability and discovered all her trips to the doctor, visits to friends, and even the exact parking spot she used when going to church. These vulnerabilities were present in Starlink systems used across the U.S., Canada, and Japan.

Method of Exploitation

The researchers identified the domain name of the website that facilitated remote control of vehicle functions. By examining the site, they found a way to gain administrative privileges. This was achieved by guessing an employee’s email address and resetting their password. The password reset process relied on answering two security questions, but the verification was handled by a local script in the user’s browser rather than on Subaru’s server, making it easy to bypass.

On LinkedIn, the researchers found the email address of a Subaru Starlink developer, broke into their account on the administrative portal, and discovered that it allowed access to any Subaru vehicle owner’s information using details like last name, zip code, email address, phone number, or license plate number. Once a vehicle was located, the system provided full access to its Starlink configuration.

s LiveTraffic
Attack on Subaru Software 6

Subaru’s Response

Curry and Shah reported their findings to Subaru in late November. The automaker promptly patched the vulnerabilities, resolving the security risks. However, the issue of data privacy remains unresolved: although potential attackers no longer have access, Subaru employees still retain the ability to track vehicles and review movement histories.

The company confirmed that its employees do have such access, but emphasized that they undergo proper training and sign confidentiality agreements. According to Subaru, this access is necessary to provide emergency responders with vehicle locations in the event of an accident detected by the system.

Broader Implications for Privacy

Subaru’s ability to track its vehicles underscores a broader issue within the auto industry—there are no guarantees of privacy anymore. Curry pointed out that, for example, a Google employee cannot access users’ Gmail messages without authorization, but Subaru employees can view detailed movement histories of their customers’ vehicles.

This incident is not isolated; earlier reports revealed similar data exposure from VW Group due to actions by its subsidiary Cariad.

Conclusion

The revelation raises serious concerns about privacy and data security in the automotive sector. While Subaru’s quick response addressed the immediate security vulnerabilities, the broader question of customer data privacy and the industry’s approach to handling sensitive information remains unresolved.

STARLINK Multimedia Overview
Attack on Subaru Software 7

Similar Posts

  • |

    Bentley Bentayga EWB 2025

    Spread the love

    Spread the loveRedefining Luxury in Extended Form Unparalleled Craftsmanship and Performance for the Modern Luxury SUV Introducing the Bentley Bentayga EWB 2025 The 2025 Bentley Bentayga EWB (Extended Wheelbase) represents the pinnacle of bespoke luxury and commanding presence in the SUV segment. Built to deliver uncompromised comfort and power, this ultra-luxurious SUV is set to…

  • Aston Martin DBX 707 2025

    Spread the love

    Spread the loveThe Pinnacle of Performance Luxury SUVs Unmatched Power. Peerless Style. Unrivaled Refinement. The SUV That Redefines Excellence The 2025 Aston Martin DBX 707 raises the bar for ultra-luxury performance SUVs. Combining the soul of a sports car with the versatility of an SUV, this powerhouse is engineered to deliver exceptional speed, superior handling,…

  • |

    Ferrari F355 GTS

    Spread the love

    Spread the loveA Timeless Icon and a Must-Have for Every Collector The Ferrari F355 GTS isn’t just a car—it’s a masterpiece of design, engineering, and passion. As one of the most iconic sports cars of the 1990s, the F355 GTS has become a highly sought-after collectible, cherished for its rarity, performance, and timeless style. But…

  • |

    Koenigsegg Regera 2025

    Spread the love

    Spread the loveThe Pinnacle of Automotive Excellence Unleashing the Future of Hypercar Performance and Innovation Introducing the Koenigsegg Regera 2025 The 2025 Koenigsegg Regera redefines the hypercar experience with its unparalleled performance, revolutionary hybrid technology, and iconic Scandinavian design. Set to make waves in the second quarter of 2025, the Regera combines raw power with…

  • | |

    BMW – Success Story

    Spread the love

    Spread the loveThe Ultimate Driving Machine and a Legacy of Innovation Introduction BMW (Bayerische Motoren Werke) is one of the most recognized and respected automotive brands in the world. Known for its precision engineering, luxury, and sporty performance, BMW has consistently delivered vehicles that combine cutting-edge technology with an exhilarating driving experience. With a deep-rooted…