logo

DARPA OnStar Vulnerability Analysis

ID: 00526ae4-b69d-574c-a28f-8ba632fbbf04

STIX ID: report--00526ae4-b69d-574c-a28f-8ba632fbbf04

Feed Name: NCC Research

Threat Score
55/100

Date Published: 2026-05-13

Date Updated: 2026-07-31

...
...

The report documents DARPA’s reproduction of academic research showing a remote attack on a vehicle Telematics Control Unit (TCU) via its analogue fallback modem: a buffer overflow in the software modem parsing audio data could be triggered by a crafted MP3 played over a phone call to the TCU, potentially allowing control of CAN-bus-connected vehicle functions (brakes, accelerator, microphone). The write-up explains the root cause (unsafe memcpy and mismatched assumptions between TCU manufacturer and telematics service provider), demonstrates the attack vector, and recommends mitigations such as secure coding, input validation, and restricting accepted call origins.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.