logo

6 Infotainment Bugs Allow Mazdas to Be Hacked With USBs

ID: fe26d02c-ae01-5040-b579-e9c9e0afcfc7

STIX ID: report--fe26d02c-ae01-5040-b579-e9c9e0afcfc7

Feed Name: Dark Reading

Threat Score
55/100

Date Published: 2024-11-08

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Six unpatched vulnerabilities were disclosed in Mazda's in-vehicle infotainment (Mazda Connect CMU) affecting recent Mazda models; the flaws—path/file sanitization issues, SQL injection via device serial number, unauthenticated SoC boot, and missing firmware verification on the VIP MCU—can enable full IVI compromise and, in ZDI research, a pivot to the vehicle CAN bus. All issues require physical insertion of a malicious USB, remain unpatched with no CVSS scores yet, and there is no reported evidence of in-the-wild exploitation, though the potential safety impact is significant if abused.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.