logo

New PerfektBlue Attack Exposes Millions of Cars to Remote Hacking

ID: b909e017-fdda-52b1-a160-2cbc28f51bed

STIX ID: report--b909e017-fdda-52b1-a160-2cbc28f51bed

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2025-07-10

Date Updated: 2026-04-21

Author: Guru Baran

...
...

**Executive Summary:** PerfektBlue is a critical chained-exploit against OpenSynergy's BlueSDK Bluetooth framework that leverages four CVE'd flaws (including a CVSS 8.0 Use-After-Free in AVRCP) to achieve one-click remote code execution on IVI systems; proof-of-concept exploits have been demonstrated on Mercedes‑Benz NTG6/NTG7, Volkswagen MEB ICAS3, and Škoda MIB3 units, exposing millions of vehicles to GPS tracking, audio surveillance, data exfiltration, and potential lateral movement to vehicle ECUs while industry patch delays widened the window of exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.