Subaru security vulnerability exposed millions of cars to tracking risks

Two security researchers discovered a security vulnerability in Subaru’s Starlink-connected vehicles last year that gave them “unrestricted targeted access to all vehicles and customer accounts” across the U.S., Canada, and Japan, according to a Wired report.

The researchers, Sam Curry and Shubham Shah, alerted the Japanese automaker to the flaws in November and they were quickly fixed. Subaru told Wired that “after being notified by independent security researchers, [Subaru] discovered a vulnerability in its Starlink service that could potentially allow a third party to access Starlink accounts. The vulnerability was immediately closed and no customer information was ever accessed without authorization.”

The researchers said that a hacker who only knew the car owner’s last name and ZIP code, email address, phone number, or license plate could remotely start, stop, lock, unlock, and retrieve the current vehicle, retrieve any vehicle’s complete location history from the past year, and find personally identifiable information of any customer.

Curry and Shah said that similar web-based flaws have been found in several other carmakers, including Kia, Honda, and Toyota.

While Curry and Shah acknowledged the security fixes, they warned that simply patching security updates after issues were found isn’t enough to remedy the more pervasive issue of privacy in the automotive industry. And even if those vulnerabilities are all remedied, employees still have access to location data.

“You can retrieve at least a year’s worth of location history for the car, where it’s pinged precisely, sometimes multiple times a day,” Curry told Wired. “Whether somebody’s cheating on their wife or getting an abortion or part of some political group, there are a million scenarios where you could weaponize this against someone.”

https://www.fastcompany.com/91266251/subaru-security-vulnerability-exposed-millions-of-cars-to-tracking-risks?partner=rss&utm_source=rss&utm_medium=feed&utm_campaign=rss+fastcompany&utm_content=rss

Created 4h | Jan 23, 2025, 9:10:03 PM


Login to add comment

Other posts in this group

A new Instagram feature might expose your embarrassing habits

Instagram Reels has added a new feature that shows you a feed of videos that your friends have liked. The bad news: It works both ways, meaning your friends can now see every video you’ve liked.&n

Jan 23, 2025, 9:10:04 PM | Fast company - tech
OpenAI’s new Operator is a step into AI’s agentic future

OpenAI announced on Thursday a research preview of Operator, an AI agent that can browse the web and perform tasks for the user. Operat

Jan 23, 2025, 9:10:02 PM | Fast company - tech
TikTok France is being sued by 7 families. Here’s why

In the moment when her world shattered three years ago, Stephanie Mistre found her 15-year-ol

Jan 23, 2025, 6:40:07 PM | Fast company - tech
The Oval Office ‘Stargate Project’ reveal was just more tech industry genuflecting

Welcome to AI DecodedFast Company’s weekly newsletter that breaks down the most important news in the world of AI. You can sign up to receive this newsletter every week 

Jan 23, 2025, 6:40:05 PM | Fast company - tech
‘Students will benefit from fewer distractions in the classroom’: Pinterest CEO supports phone-free schools

Pinterest’s CEO wants teens to use their app, but not during school hours. 

Bill Ready has joined the growing chorus of parents, educators, and policymakers advocating for “phone-fr

Jan 23, 2025, 6:40:04 PM | Fast company - tech
What to do when you can’t escape your old boss on social media

There are certain social media rules we can all agree on: Ghosting a conversation is impolite, and replying “k” to a text is the equivalent of a backhand slap (violent, wrong, and rude). But what

Jan 23, 2025, 11:40:05 AM | Fast company - tech