Most Viewed Content:

India’s censorship body gave power to remove pirated Movies from platforms

India’s Ministry of Information and Broadcasting announced that its...

OpenAI Launched Assistants API, Allowing Developers to Customize AI Assistants with One Click

At today's OpenAI's first developer conference, OpenAI launched the...

Microsoft working on new features for Win11 / Win12: smart notifications, depth-of-field effects

According to the source Albacore (@thebookisclosed), Microsoft is preparing...

Security experts announced multiple vulnerabilities affecting millions of vehicles including Mercedes-Benz and BMW

Security experts have recently discovered a security vulnerability affecting millions of cars, affecting almost all major car brands in the world. Hackers can exploit vulnerabilities in your car’s telematics system, car APIs, and supporting infrastructure to do everything from remote control to a complete takeover of your car.

Mercedes-Benz, BMW, Rolls-Royce, Ferrari, Ford, Porsche, Toyota, Jaguar, and Land Rover have been affected, as well as fleet management company Spireon and digital license plate company Reviver.

Sam Curry of Yuga Labs found vulnerabilities in several Hyundai and Genesis models during his research on cracking cars, and found that Sirius XM’s Connected Vehicle Services vulnerability affects Honda, Nissan, Infiniti and Acuras.

“The affected companies all fixed the issues within a day or two of reporting them. We worked with all of these companies to validate them and make sure there were no bypasses for these vulnerabilities,” Curry said.

Based on Curry’s vulnerability research, security experts have successively discovered multiple security vulnerabilities with a wide range. From a public safety standpoint, the most serious breach was discovered at Spireon, which owns several GPS vehicle tracking and fleet management brands, including OnStar, GoldStar, LoJack, FleetLocate and NSpire, covering 15 million connected vehicles.

Curry and team discovered multiple vulnerabilities in SQL injection and authorization bypass, allowing remote code execution on all Spireons and complete takeover of any fleet vehicle.

“This will allow us to track and deactivate the starters of police, ambulance and law enforcement vehicles in a number of different large cities and issue commands to these vehicles,” the researchers wrote.

“The vulnerabilities also gave them full administrator access to Spireon Corporation and a company-wide admin panel from which an attacker could send arbitrary commands to all 15 million vehicles to remotely unlock the doors,” the researchers wrote. , honk, start the engine and disable the starter”.

Additionally, the researchers discovered an over-permission access control vulnerability targeting Ferrari cars that allowed them to access the JavaScript code of several internal applications. The code contained API keys and credentials that could have allowed an attacker to access customer records and take over (or delete) customer accounts.

The researchers say an attacker could POST to the “/core/api/v1/Users/:id/Roles” endpoint, edit their user roles, set themselves to have superuser privileges or become a Ferrari owner.

Latest

Google Android 15: Restricts sideloaded apps from obtaining sensitive permissions

Foreign technology media Android Authority recently excavated the latest...

Mercedes-Benz G 580 off-road EV officially released

Mercedes-Benz today released a new pure electric G-Class off-road...

Chery iCAR 03T preview image released, will debut at Beijing Auto Show

Today Chery Automobile officially released a preview image of...

Redmi 13 5G passed 3C certification, support 33W charging

Xiaomi released the Redmi 12 5G phone in August...

Newsletter

Don't miss

Google Android 15: Restricts sideloaded apps from obtaining sensitive permissions

Foreign technology media Android Authority recently excavated the latest...

Mercedes-Benz G 580 off-road EV officially released

Mercedes-Benz today released a new pure electric G-Class off-road...

Chery iCAR 03T preview image released, will debut at Beijing Auto Show

Today Chery Automobile officially released a preview image of...

Redmi 13 5G passed 3C certification, support 33W charging

Xiaomi released the Redmi 12 5G phone in August...

Pony.ai Unveils Seventh-Generation Pure Electric Robotaxi Concept Car

Pony.ai announced today that it will display the seventh-generation...
Threza Gabriel
Threza Gabrielhttps://www.techgoing.com
Threza Gabriel is a news writer at TechGoing. TechGoing is a global tech media to brings you the latest technology stories, including smartphones, electric vehicles, smart home devices, gaming, wearable gadgets, and all tech trending.

Samsung Galaxy C55 display machine spotted in offline stores with stitched plain leather back cover

The Samsung Galaxy C55 display machine has been put on display in offline stores. It is equipped with the Snapdragon 7 Gen 1 chip...

Ericsson confirms layoffs in China, affecting “core network” R&D department

Last month Ericsson reported that it was making strategic adjustments to its business in China and that there were large-scale layoffs in R&D positions....

Elon Musk: Tesla is streamlining sales and delivery system

Tesla CEO Elon Musk posted on the social media platform X that Tesla was streamlining its sales and delivery system. Elon Musk said the...