Subaru Starlink flaw let hackers hijack cars in US and Canada
ID: cadfe915-e872-5ca4-bd3d-5c04f4017299
STIX ID: report--cadfe915-e872-5ca4-bd3d-5c04f4017299
Feed Name: Bleeping Computer
Security researchers disclosed an arbitrary account takeover vulnerability in Subaru's Starlink admin portal that—using only minimal identifiers such as a license plate—could let an attacker access and control vehicles, retrieve precise location history (past year, ~5m accuracy), and extract customer PII and vehicle data across the United States, Canada, and Japan; the issue was demonstrated by researchers, patched by Subaru within 24 hours, and reported as not exploited in the wild.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
