Subaru security vulnerability exposed millions of cars to tracking risks

Two security researchers discovered a security vulnerability in Subaru’s Starlink-connected vehicles last year that gave them “unrestricted targeted access to all vehicles and customer accounts” across the U.S., Canada, and Japan, according to a Wired report.

The researchers, Sam Curry and Shubham Shah, alerted the Japanese automaker to the flaws in November and they were quickly fixed. Subaru told Wired that “after being notified by independent security researchers, [Subaru] discovered a vulnerability in its Starlink service that could potentially allow a third party to access Starlink accounts. The vulnerability was immediately closed and no customer information was ever accessed without authorization.”

The researchers said that a hacker who only knew the car owner’s last name and ZIP code, email address, phone number, or license plate could remotely start, stop, lock, unlock, and retrieve the current vehicle, retrieve any vehicle’s complete location history from the past year, and find personally identifiable information of any customer.

Curry and Shah said that similar web-based flaws have been found in several other carmakers, including Kia, Honda, and Toyota.

While Curry and Shah acknowledged the security fixes, they warned that simply patching security updates after issues were found isn’t enough to remedy the more pervasive issue of privacy in the automotive industry. And even if those vulnerabilities are all remedied, employees still have access to location data.

“You can retrieve at least a year’s worth of location history for the car, where it’s pinged precisely, sometimes multiple times a day,” Curry told Wired. “Whether somebody’s cheating on their wife or getting an abortion or part of some political group, there are a million scenarios where you could weaponize this against someone.”

https://www.fastcompany.com/91266251/subaru-security-vulnerability-exposed-millions-of-cars-to-tracking-risks?partner=rss&utm_source=rss&utm_medium=feed&utm_campaign=rss+fastcompany&utm_content=rss

Vytvorené 6mo | 23. 1. 2025, 21:10:03


Ak chcete pridať komentár, prihláste sa

Ostatné príspevky v tejto skupine

This free site is like Google Maps for local food discovery

As my family settles into a whole new city and community, I’ve been eagerly exploring a variety of sites and services for discovering new gems and getting to know our area. And while our recent cr

24. 7. 2025, 11:20:08 | Fast company - tech
He helped kids be creative. Now, he wants to do the same for CEOs

More than a decade ago, Pramod Sharma set out to make learning more engaging. Through

24. 7. 2025, 11:20:07 | Fast company - tech
This tool lets users send fake legal letters that look real—without a lawyer

If you can’t afford a lawyer, it turns out there’s nothing stopping you from sending a scary-looking letter that, at first glance, seems to come from one—and hoping the recipient doesn’t read the

24. 7. 2025, 9:10:03 | Fast company - tech
9 essential Perplexity AI search tips and tricks

All right, settle in, folks, because today we’re going to try to out-Google Google with the next generation of search: Perplexity.

So, what exactly is

24. 7. 2025, 6:40:07 | Fast company - tech
Tokenization is gaining ground in the crypto world. Here’s what to know

Tokenization has long been a buzzword for crypto enthusiasts, who have been arguing for years that blo

23. 7. 2025, 21:30:05 | Fast company - tech
‘Door kick challenge’ goes viral—but cops say the TikTok trend could lead to serious injury

Ding dong ditching has resurfaced as the “door kick challenge.” But this time it could lead to criminal charges and potentially deadly consequences. 

In Florida this week, five mino

23. 7. 2025, 21:30:04 | Fast company - tech
Alphabet’s Q2 revenue beats estimates as cloud computing surges

Alphabet beat Wall Street estimates for its second quarter on Wednesday, and cited massive

23. 7. 2025, 21:30:03 | Fast company - tech