Car Infotainment Vulnerability Raises Supply Chain Concerns
ID: 05825f3f-37da-5eaa-ab0d-9fb56bdee923
STIX ID: report--05825f3f-37da-5eaa-ab0d-9fb56bdee923
Feed Name: Security Ledger
Researchers from George Mason University and New York University found multiple vulnerabilities in MirrorLink in-vehicle infotainment software that could let a compromised smartphone send crafted messages to an IVI unit and potentially inject arbitrary messages onto the vehicle CAN bus; the MirrorLink client was implemented in C++ running with high privileges on WinCE and contained heap-overflow and memory-safety issues that could be escalated to control the IVI application and interact with vehicle controllers. The paper documents the technical flaws and highlights broader concerns about third-party IVI components exposing critical vehicle subsystems, though no active exploitation in the wild is reported.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
