PerfektBlue Bluetooth Flaws Risk Millions of Vehicles to Remote Attacks

Published:

spot_img

Major Bluetooth Vulnerabilities Exposed in Automotive Systems

Cybersecurity experts have unveiled serious vulnerabilities in OpenSynergy’s BlueSDK Bluetooth stack that can jeopardize millions of vehicles from several leading manufacturers. Dubbed PerfektBlue, these vulnerabilities have the potential to facilitate remote code execution, creating significant concerns for vehicle security.

What is PerfektBlue?

The PerfektBlue vulnerabilities comprise four critical security flaws that can be combined into an exploit chain, enabling unauthorized code execution on the In-Vehicle Infotainment (IVI) systems of cars manufactured by well-known brands like Mercedes-Benz, Volkswagen, and Skoda. Reports also confirm that an additional unnamed vehicle manufacturer is affected by these vulnerabilities.

Technical Details of the Vulnerabilities

According to PCA Cyber Security, the exploitation of PerfektBlue hinges on several memory corruption and logical vulnerabilities within the BlueSDK. These flaws can enable attackers to launch a Remote Code Execution (RCE) attack, raising the stakes for automotive cybersecurity.

The vulnerabilities identified include:

  • CVE-2024-45434: A critical Use-After-Free vulnerability in the AVRCP service (CVSS score: 8.0).
  • CVE-2024-45431: A moderate flaw concerning the improper validation of a remote CID in an L2CAP channel (CVSS score: 3.5).
  • CVE-2024-45433: An issue with function termination in RFCOMM (CVSS score: 5.7).
  • CVE-2024-45432: An incorrect parameter in a function call within RFCOMM (CVSS score: 5.7).

How the Attack Works

A significant concern is that executing the attack requires minimal technical expertise. An attacker simply needs to be within Bluetooth range of a targeted vehicle’s infotainment system to initiate the exploitation. The process is almost akin to a single-click attack, allowing the unauthorized access to be triggered over wireless networks. The extent to which this attack is feasible can vary based on how each automotive manufacturer implements their frameworks.

Implications for Vehicle Security

Once an attacker gains access to a vehicle’s IVI system, they can perform a range of unauthorized actions. These include tracking the vehicle’s GPS location, accessing contact lists, and even infiltrating more critical vehicle functions such as engine control. The method to maintain communication with the vehicle, once compromised, can allow for extensive control over various functions.

Vulnerability Mitigation

Following a responsible disclosure in May 2024, manufacturers have rolled out security patches to address these vulnerabilities by September 2024. However, the severity of these flaws highlights the need for continuous vigilance within the automotive industry regarding cybersecurity measures.

Examples from the Field

In April 2024, PCA Cyber Security also outlined methods to remotely infiltrate a Nissan Leaf electric vehicle using similar Bluetooth vulnerabilities to take control over essential functionalities. The approach involved exploiting Bluetooth weaknesses to break into internal networks, bypassing secure boot processes for enhanced access.

Through the establishment of a Command-and-Control (C2) channel over DNS, attackers can secure ongoing remote control, tapping directly into the CAN bus. This fundamental communication protocol is vital for managing critical vehicle systems, including locks and steering functions.

The Risks of CAN Bus Exploits

The vulnerabilities related to the Controller Area Network (CAN) create an avenue for attackers with physical access to a vehicle to execute injection attacks. One notable example involves the use of small electronic devices inserted in innocuous objects, which can mimic authorized messages within the CAN bus. By doing so, these rogue devices can unlock doors or start the engine, posing a severe threat to vehicular security.

Recent Investigations

A recent report by Pen Test Partners revealed an innovative yet alarming exploit, transforming a 2016 Renault Clio into a controller for a Mario Kart game by intercepting and manipulating CAN bus data. This not only showcases the vulnerabilities present in modern automotive systems but also emphasizes the potential for creative, albeit malicious, uses of such exploits.


For vehicle owners and manufacturers alike, understanding these vulnerabilities and their implications is crucial to ensuring safety and security on the roads.

spot_img

Related articles

Recent articles

Origin Energy Data Breach 2026: Unauthorized Access Exposes PII of 900,000 Customers

On July 28, 2026, Origin Energy confirmed a significant data breach impacting approximately 900,000 current and former customers. This incident involved unauthorized access and...

Mirage Kitten Unveils NightLedger Backdoor and WebSocket Tunnelers for Cyber-Espionage in Middle East and Africa

Recent research has unveiled a new set of malware tools attributed to the advanced persistent threat (APT) group known as Mirage Kitten, which is...

Bank of Baroda Reports Cybersecurity Incident Following Alleged Data Theft Claims

Bank of Baroda, one of India's largest state-owned banks, has reported a cybersecurity incident following claims from a threat actor regarding the theft and...

Fairlife resumes US production after ransomware attack, data breach confirmed

USA – The Coca-Cola Company has announced that its dairy subsidiary Fairlife has resumed most production across its four US facilities following a ransomware...