logo

Multiple flaws in Volkswagen Group’s infotainment unit allow for vehicle compromise

ID: 40b0a72b-d008-5b33-95ac-3a9e4279f7fa

STIX ID: report--40b0a72b-d008-5b33-95ac-3a9e4279f7fa

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2024-12-16

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Researchers from PCAutomotive disclosed a set of vulnerabilities in VW Group MIB3 infotainment units (including units by Preh Car Connect GmbH) that could allow unauthenticated attackers in proximity to exploit Bluetooth/phonebook parsing and other services to cause code execution, track vehicles in real time, access GPS and contacts, monitor speed, record in-car conversations, and more; 12 CVEs are listed, a video PoC was published, and the vendor reports some fixes are deployed while others are being addressed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.