Subaru security vulnerability exposed millions of cars to tracking risks

Two security researchers discovered a security vulnerability in Subaru’s Starlink-connected vehicles last year that gave them “unrestricted targeted access to all vehicles and customer accounts” across the U.S., Canada, and Japan, according to a Wired report.

The researchers, Sam Curry and Shubham Shah, alerted the Japanese automaker to the flaws in November and they were quickly fixed. Subaru told Wired that “after being notified by independent security researchers, [Subaru] discovered a vulnerability in its Starlink service that could potentially allow a third party to access Starlink accounts. The vulnerability was immediately closed and no customer information was ever accessed without authorization.”

The researchers said that a hacker who only knew the car owner’s last name and ZIP code, email address, phone number, or license plate could remotely start, stop, lock, unlock, and retrieve the current vehicle, retrieve any vehicle’s complete location history from the past year, and find personally identifiable information of any customer.

Curry and Shah said that similar web-based flaws have been found in several other carmakers, including Kia, Honda, and Toyota.

While Curry and Shah acknowledged the security fixes, they warned that simply patching security updates after issues were found isn’t enough to remedy the more pervasive issue of privacy in the automotive industry. And even if those vulnerabilities are all remedied, employees still have access to location data.

“You can retrieve at least a year’s worth of location history for the car, where it’s pinged precisely, sometimes multiple times a day,” Curry told Wired. “Whether somebody’s cheating on their wife or getting an abortion or part of some political group, there are a million scenarios where you could weaponize this against someone.”

https://www.fastcompany.com/91266251/subaru-security-vulnerability-exposed-millions-of-cars-to-tracking-risks?partner=rss&utm_source=rss&utm_medium=feed&utm_campaign=rss+fastcompany&utm_content=rss

Creado 7mo | 23 ene 2025, 21:10:03


Inicia sesión para agregar comentarios

Otros mensajes en este grupo.

The Army is tapping influencers to win over Gen Z recruits

The U.S. Army is turning to sponcon to reach Gen Z. 

Steven Kelly, who has more than 1.3 million Instagram followe

26 ago 2025, 17:10:06 | Fast company - tech
AI chatbots are inconsistent with suicide-related questions, study says

EDITOR’S NOTE — This story includes discussion of suicide. If you or someone you know needs help, the national suicide and crisis lifeline in the U.S. is available by calling or texting 988.

26 ago 2025, 17:10:05 | Fast company - tech
Netflix is doubling down on full-season drops with season two of Meghan’s show

Meghan, Duchess of Sussex’ latest season of her reality show, With Love, Meghan, drops today on Netflix. In line with the stream

26 ago 2025, 14:40:16 | Fast company - tech
Listen to the 10 most memorable sound effects in the history of tech

For understandable reasons, most technology coverage tends to focus more on the physical or visual

26 ago 2025, 14:40:15 | Fast company - tech
Where solar investments pack the biggest climate punch

The United States’ hourly demand for electricity broke two records last month, reaching its highest-ever level—759,190 megawatts

26 ago 2025, 14:40:14 | Fast company - tech
Doctors love this AI app because it gives them hours of their lives back

A typical physician’s job is much more than just seeing patients. In fact, most doctors spend hours every week outside of clinic hours catching up on typing notes and getting visits and trea

26 ago 2025, 14:40:12 | Fast company - tech
Agentic AI has companies excited and security experts freaked out

Agentic AI is being heralded as the future of the generative AI revolu

26 ago 2025, 12:30:04 | Fast company - tech