Security Flaw Found in Subaru’s Connected Vehicle System

Published:

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

Major Security Flaw Exposed in Subaru’s STARLINK Service: Unrestricted Access to User Accounts and Vehicles at Risk

Subaru’s STARLINK Service Exposed: Major Vulnerability Poses Security Risk to Users

In a troubling revelation, cybersecurity researchers Shubham Shah and Sam Curry have identified a significant vulnerability within Subaru’s STARLINK connected vehicle service, affecting users across the United States, Canada, and Japan. This flaw allows unauthorized access to all user accounts and vehicle controls if a malicious actor possesses sensitive personal information such as a user’s surname and ZIP code.

By taking advantage of this security gap, hackers could potentially track vehicle locations, remotely control essential functions like locking or starting the car, and even glean a year’s worth of location history and other sensitive data, including odometer readings and previous owners. Josh Jacobson, Director of Professional Services at HackerOne, explained that hardcoded credentials within JavaScript files enabled researchers to bypass security measures, gaining full administrative access to any STARLINK-connected vehicle.

The implications are dire, as Clyde Williamson, Senior Product Security Architect at Protegrity, noted, “Hackers could exploit this data not only to identify individuals but also to orchestrate targeted social engineering attacks.” These risks extend beyond the vehicle itself to the personal lives of users, raising alarms about safety and privacy.

As connected vehicles proliferate, experts highlight the inadequacy of security measures, pointing to the outdated CAN bus protocol designed without modern safeguarding. Williamson urged manufacturers to adopt robust data protection strategies, such as encryption, to combat potential exploitation.

The lack of transparency around data collection practices has left consumers vulnerable, often unaware of the sensitive information they unwittingly provide. With regulatory oversight faltering, the call for stronger legislation and proactive data security measures in the automotive industry has never been more urgent. As technology advances, protecting users must remain a top priority.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

CISA Unveils Plan to Enhance Quality of Common Vulnerabilities and Exposures Program Amid Rising CVE Submissions

The Cybersecurity and Infrastructure Security Agency (CISA) has released a white paper outlining its strategy to enhance the Common Vulnerabilities and Exposures (CVE) program,...

Red Hat releases important kernel security update for RHEL 8.6 Advanced and Extended Support

Red Hat has announced a significant kernel security update for its Red Hat Enterprise Linux (RHEL) 8.6 Advanced Mission Critical Update Support and RHEL...

Syria seeks to transform Russian military bases into training centers

Syria is seeking to transform Russian military bases into training centers for its own armed forces, as part of a broader strategy to eliminate...

Armenian National Sentenced to Two Years for Role in Ryuk Ransomware Attacks

An Armenian national has been sentenced to two years in U.S. federal prison after pleading guilty to charges related to multiple ransomware attacks. Karen...