Subaru security vulnerability exposed millions of cars to tracking risks

Two security researchers discovered a security vulnerability in Subaru’s Starlink-connected vehicles last year that gave them “unrestricted targeted access to all vehicles and customer accounts” across the U.S., Canada, and Japan, according to a Wired report.

The researchers, Sam Curry and Shubham Shah, alerted the Japanese automaker to the flaws in November and they were quickly fixed. Subaru told Wired that “after being notified by independent security researchers, [Subaru] discovered a vulnerability in its Starlink service that could potentially allow a third party to access Starlink accounts. The vulnerability was immediately closed and no customer information was ever accessed without authorization.”

The researchers said that a hacker who only knew the car owner’s last name and ZIP code, email address, phone number, or license plate could remotely start, stop, lock, unlock, and retrieve the current vehicle, retrieve any vehicle’s complete location history from the past year, and find personally identifiable information of any customer.

Curry and Shah said that similar web-based flaws have been found in several other carmakers, including Kia, Honda, and Toyota.

While Curry and Shah acknowledged the security fixes, they warned that simply patching security updates after issues were found isn’t enough to remedy the more pervasive issue of privacy in the automotive industry. And even if those vulnerabilities are all remedied, employees still have access to location data.

“You can retrieve at least a year’s worth of location history for the car, where it’s pinged precisely, sometimes multiple times a day,” Curry told Wired. “Whether somebody’s cheating on their wife or getting an abortion or part of some political group, there are a million scenarios where you could weaponize this against someone.”

https://www.fastcompany.com/91266251/subaru-security-vulnerability-exposed-millions-of-cars-to-tracking-risks?partner=rss&utm_source=rss&utm_medium=feed&utm_campaign=rss+fastcompany&utm_content=rss

Vytvořeno 6mo | 23. 1. 2025 21:10:03


Chcete-li přidat komentář, přihlaste se

Ostatní příspěvky v této skupině

Trump’s FTC is spreading lies about trans people. This bill would let it wipe them off the internet

The Federal Trade Commission (FTC) was created in 1914 to protect consumers from corporate overreach. Under Donald Trump, the 110-year-old bipartisan agency is now being converted into a weapon of

31. 7. 2025 17:20:13 | Fast company - tech
How Google is working with Hollywood to bring AI to filmmaking

Welcome to AI DecodedFast Company’s weekly newsletter that breaks down the most imp

31. 7. 2025 17:20:11 | Fast company - tech
What Buddhism would say about AI avatars of the dead

In a story in the Buddhist canon, a grief-stricken mother named Kisa Gautami loses her only child and carries th

31. 7. 2025 17:20:08 | Fast company - tech
This Texas startup built a data center for the night sky with 400 telescopes

In a former cattle field in rural central Texas, a startup called Starfront has quietly built what it claims is the world’s largest remote telescope observato

31. 7. 2025 12:40:07 | Fast company - tech
‘The overall vibe was total chaos’: Tesla Diner goes viral for long waits and mixed reviews

In case you’ve been living under a rock and haven’t heard, the Tesla Diner

31. 7. 2025 5:40:07 | Fast company - tech