Subaru security vulnerability exposed millions of cars to tracking risks

Two security researchers discovered a security vulnerability in Subaru’s Starlink-connected vehicles last year that gave them “unrestricted targeted access to all vehicles and customer accounts” across the U.S., Canada, and Japan, according to a Wired report.

The researchers, Sam Curry and Shubham Shah, alerted the Japanese automaker to the flaws in November and they were quickly fixed. Subaru told Wired that “after being notified by independent security researchers, [Subaru] discovered a vulnerability in its Starlink service that could potentially allow a third party to access Starlink accounts. The vulnerability was immediately closed and no customer information was ever accessed without authorization.”

The researchers said that a hacker who only knew the car owner’s last name and ZIP code, email address, phone number, or license plate could remotely start, stop, lock, unlock, and retrieve the current vehicle, retrieve any vehicle’s complete location history from the past year, and find personally identifiable information of any customer.

Curry and Shah said that similar web-based flaws have been found in several other carmakers, including Kia, Honda, and Toyota.

While Curry and Shah acknowledged the security fixes, they warned that simply patching security updates after issues were found isn’t enough to remedy the more pervasive issue of privacy in the automotive industry. And even if those vulnerabilities are all remedied, employees still have access to location data.

“You can retrieve at least a year’s worth of location history for the car, where it’s pinged precisely, sometimes multiple times a day,” Curry told Wired. “Whether somebody’s cheating on their wife or getting an abortion or part of some political group, there are a million scenarios where you could weaponize this against someone.”

https://www.fastcompany.com/91266251/subaru-security-vulnerability-exposed-millions-of-cars-to-tracking-risks?partner=rss&utm_source=rss&utm_medium=feed&utm_campaign=rss+fastcompany&utm_content=rss

Creată 6mo | 23 ian. 2025, 21:10:03


Autentifică-te pentru a adăuga comentarii

Alte posturi din acest grup

No, you don’t need to get 10,000 steps per day

The gospel according to fitness influencers: drink three liters of water per day, get a minimum of eight hours of sleep, and walk at least 10,000 steps per day.

From the

30 iul. 2025, 20:30:11 | Fast company - tech
White House to release highly anticipated crypto policy report

A cryptocurrency working group formed by President Donald Trump is set to release a report on Wednesday that is expected to outline t

30 iul. 2025, 20:30:09 | Fast company - tech
Google is indexing ChatGPT conversations, potentially exposing sensitive user data

Google is indexing conversations with ChatGPT that users have sent to friends, families, or colleagues—turning private exchanges intended for small groups into search results visible to millions.

30 iul. 2025, 20:30:04 | Fast company - tech
‘I legitimately smelled like onion’: TikTok users are ditching natural deodorant and going back to antiperspirant

It’s hot. Everyone is sweating, and anyone who chooses to venture into the world armed with nothing but natural deodorant knows they’re playing a risky game.

But online, the backlash aga

30 iul. 2025, 18:10:06 | Fast company - tech
This influencer is braving the brutal summer without A/C to help families pay electric bills

If you’ve been thanking the heavens for your A/C this week, spare a thought for Paul Farmer, who’s enduring the peak of Arizona’s summer without it—by choice.

Last year, Farmer went with

30 iul. 2025, 15:50:04 | Fast company - tech
Panasonic announces new CEO, a former Boeing executive

Japanese electronics and technology company Panasonic has chosen a new chief executive after eking out a 1.2% rise in its first quarter

30 iul. 2025, 15:50:03 | Fast company - tech
How Cloudflare declared war on AI scrapers

Cloudflare supports more than 20% of total internet traffic. The company recently made headlines with breakthrough technology that blocks

30 iul. 2025, 13:30:04 | Fast company - tech