Security Experts Hack Into Moving Car and Seize Control

Advertisement
By Reuters | Updated: 22 July 2015 12:25 IST
A pair of veteran cyber-security researchers have shown they can use the Internet to turn off a car's engine as it drives, sharply escalating the stakes in the debate about the safety of increasingly connected cars and trucks.

Former National Security Agency hacker Charlie Miller, now at Twitter, and IOActive researcher Chris Valasek used a feature in the Fiat Chrysler telematics system Uconnect to break into a car being driven on the highway by a reporter for technology news site Wired.com.

In a controlled test, they turned on the Jeep Cherokee's radio and activated other inessential features before rewriting code embedded in the entertainment system hardware to issue commands through the internal network to steering, brakes and the engine.

Advertisement

"There are hundreds of thousands of cars that are vulnerable on the road right now," Miller told Reuters.

Fiat Chrysler said it had issued a fix for the most serious vulnerability involved. The software patch is available for free on the company's website and at dealerships.

Advertisement

"Similar to a smartphone or tablet, vehicle software can require updates for improved security protection to reduce the potential risk of unauthorised and unlawful access to vehicle systems," the company said. It didn't immediately answer other questions.

Miller and Valasek have been probing car safety for years and have been among those warning that remote hacking was inevitable. An academic team had previously said it hacked a moving vehicle from afar but did not say how or name the manufacturer, putting less pressure on the industry.

Advertisement

National Highway Traffic Safety Administration chief Mark Rosekind on Tuesday said his agency is increasingly concerned about the security of vehicle control systems.

"We know these systems will become targets of bad actors," he told a conference on autonomous and connected vehicle technology in Ypsilanti, Mich. If consumers don't believe that connected vehicle systems are safe and secure, he said, "they will not engage it."

Advertisement

Members of Congress have also expressed concern, and on Tuesday senators Ed Markey and Richard Blumenthal, both Democrats, introduced a bill that would direct the NHTSA to develop standards for isolating critical software and detect hacking as it occurs.

Miller and Valasek said they had been working with Fiat Chrysler since October, giving the company enough time to construct a patch to disable a feature that the men suspected had been turned on by accident. They plan to release a paper at the Def Con security conference next month that includes code for remote access, which will no longer work on cars that have been updated.

They said the harder problem for an attacker, moving from the entertainment system to the core onboard network, would take months for other top-tier hackers to emulate.

Many Jeeps could remain unpatched, leaving them open to attack. But the researchers said hackers would need to know the Internet Protocol address of a car in order to attack it specifically, and that address changes every time the car starts.

Otherwise, "You have to attack random cars," Valasek said.

The men stressed that it would be easy to make modest adjustments to their code and attack other types of vehicles.

They said that manufacturers, who are racing to add new Internet-connected features, should work much harder on creating safe capability for automatic over-the-air software updates, segregation of onboard entertainment and engineering networks, and intrusion-detection software for stopping improper commands.

"Anything that connects to the outside world is an attack vector, from my point of view," Valasek said.

© Thomson Reuters 2015

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. OTT Releases This Week: 24, Band Melam, Nukkad Naatak, Prathichaya, and More
  2. Vivo Y6 5G Debuts With 7,200mAh Battery, 6.75-Inch Screen at This Price
  3. Honor Earbuds 4 With Up to 46 Hours of Total Battery Life Debut Globally
  4. Qualcomm Hints at Snapdragon Chips for Samsung Galaxy S27 Series
  5. Detailed Oppo Find X9 Ultra Teardown Video Shows Us What's Inside
  6. Assassin's Creed Black Flag Resynced Revealed: Everything You Need to Know
  7. Vivo X300 Ultra Content Creation Features Showcased Ahead of India Launch
  8. Xbox Chief Asha Sharma Sets New Strategy, Says Will Reevaluate Exclusives
  9. OnePlus Says This Chip Will Help the Ace 6 Ultra Offer Longer Battery Life
  10. Redmi Note 17 Pro Max Leak Reveals Chipset, Camera Details
  1. Microsoft Gaming Rebrands to Xbox, Debuts New Logo as Xbox Chief Says Company Reevaluating Exclusive Games
  2. Prathichaya (2026) Now Streaming Online: What You Need to Know
  3. Kelp Exploit Aftermath: DeFi Protocols Join Hands to Restore rsETH Following $293 Million Hack
  4. Microsoft Makes Copilot’s Agentic Features in Word, Excel and PowerPoint Generally Available
  5. OnePlus Ace 6 Ultra Battery Capacity Revealed as Company Teases ‘Energy Concentration’ Chip
  6. Mension House Mallesh Now Available for Streaming Online: Where to Watch This Telugu Romantic Comedy Drama Online?
  7. Redmi A7 4G, Redmi A7 Pro 4G With Unisoc T7250 Chip, 13-Megapixel Rear Camera Go on Sale in India
  8. Xiaomi Mix Fold 5 Reportedly in Development With In-House Xring O3 Chip
  9. Qualcomm Seemingly Confirms Samsung Galaxy S27 Series Will Feature Next-Generation Snapdragon Chips
  10. Ethereum Slips Below $2,300 as Bitcoin Price Steadies Amid Profit Booking
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.