Man-in-the-Middle Vulns Threaten Car Security
ID: 05e3af72-000a-52d1-ac01-604c80f75b6d
STIX ID: report--05e3af72-000a-52d1-ac01-604c80f75b6d
Feed Name: Dark Reading
Date Published: 2025-03-14
Date Updated: 2026-04-21
Author: Kristina Beek, Associate Editor, Dark Reading
Executive summary: Security researchers uncovered two vulnerabilities in a major China-based automaker's products affecting over 150,000 vehicles sold in 2024: an IVI (infotainment) vulnerability enabling low-privilege code execution and limited vehicle control (doors, trunk, windows, headlights) via pivoting, and an unsecured mobile app susceptible to man-in-the-middle attacks through fake certificate injection that can yield tokens for remote control. The researchers describe the MiTM techniques as "beginner-level," emphasize the broader industry gap in automotive software security, and will present their findings at Black Hat Asia; the report does not indicate active exploitation in the wild.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
