logo

Man-in-the-Middle Vulns Threaten Car Security

ID: 05e3af72-000a-52d1-ac01-604c80f75b6d

STIX ID: report--05e3af72-000a-52d1-ac01-604c80f75b6d

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2025-03-14

Date Updated: 2026-04-21

Author: Kristina Beek, Associate Editor, Dark Reading

...
...

Executive summary: Security researchers uncovered two vulnerabilities in a major China-based automaker's products affecting over 150,000 vehicles sold in 2024: an IVI (infotainment) vulnerability enabling low-privilege code execution and limited vehicle control (doors, trunk, windows, headlights) via pivoting, and an unsecured mobile app susceptible to man-in-the-middle attacks through fake certificate injection that can yield tokens for remote control. The researchers describe the MiTM techniques as "beginner-level," emphasize the broader industry gap in automotive software security, and will present their findings at Black Hat Asia; the report does not indicate active exploitation in the wild.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.