Keyless Systems of Older VW Group Cars Can Be Hacked: Study

Advertisement
By Reuters | Updated: 12 August 2016 18:13 IST
Tens of millions of vehicles sold by Volkswagen AG over the past 20 years are vulnerable to theft because keyless entry systems can be hacked using cheap technical devices, according to European researchers.

Computer security experts at the University of Birmingham have published a paper outlining how they were able to clone VW remote keyless entry controls by eavesdropping nearby when drivers press their key fobs to open or lock up their cars.

Vehicles vulnerable to this attack include most Audi, VW, Seat and Skoda models sold since 1995 and many of the approximately 100 million VW Group vehicles on the road since then, the researchers said. The flaw was found in car models as recent as the Audi Q3, model year 2016, they added.

Advertisement

"It is conceivable that all VW Group (except for some Audi) cars manufactured in the past and partially today rely on a 'constant-key' scheme and are thus vulnerable to the attacks," the paper argues.

The only exception the researchers found were cars built on VW's latest MQB production platform, which is used in its top selling model, the Golf VII, which they found does not have the keyless flaw.

Advertisement

A VW spokesman said that the current Golf, Tiguan, Touran and Passat models are not vulnerable to the attack.

"This current vehicle generation is not afflicted by the problems described," VW spokesman Peter Weisheit said in a statement, without commenting on the risks to other models.

Advertisement

In their published paper, the researchers did not identify the auto parts subcontractor responsible for manufacturing the affected keyless systems for VW and potentially other car makers. VW declined to comment on its supplier relationships.

The disclosures come as Europe's largest automaker struggles to overcome its biggest-ever corporate scandal, after it admitted to manipulating diesel emissions tests in about 11 million vehicles globally.

Advertisement

Other car makers vulnerable
Attackers can use cheap and widely available tools for grabbing radio signals, according to the three researchers from the University of Birmingham in central England and a fourth affiliated with the University of Bochum in Germany.

Cars from other manufacturers may share these flaws, including some model years of the Ford Galaxy, the security researchers said.

A spokesman for Ford Europe had no immediate comment.

The reports' authors said they had focused on mass-market models and did not analyse in detail VW's luxury brands including Porsche, Bentley, Lamborghini and Bugatti.

Researchers including University of Birmingham computer science lecturer Flavio Garcia said they disclosed their findings to VW Group from November and met the company and the subcontractor involved in February.

VW Group received a draft and a final copy of the research paper before publication and have acknowledged the vulnerabilities, the authors said.

The Wolfsburg-based automaker confirmed it has had a constructive exchange with the researchers and that they had agreed to withhold details that savvy criminals could use to break into cars.

In 2013, VW obtained a restraining order against a group of researchers including Garcia to prevent publication of a paper detailing how anti-theft car immobilisers used by more than 20 different automakers were vulnerable to hacker attacks.

That research was eventually published in 2015 after the authors agreed with VW to remove a pivotal detail that would have allowed low-tech thieves to figure out how to carry out the attack.

The latest paper, entitled "Lock It and Still Lose It: On the (In)Security of Automotive Remote Keyless Entry Systems" is scheduled to be presented at the prestigious Usenix computer security conference in Austin, Texas, on Friday.

© Thomson Reuters 2016

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Hacking, Internet, Volkswagen
Advertisement

Related Stories

Popular Mobile Brands
  1. Flipkart Big Billion Days Sale 2026: iPhone 17, iPhone 15 Deals Revealed
  2. Amazon Great Indian Festival Sale 2026: Top Early Deals Live Right Now
  3. Flipkart Big Billion Days Sale: These Motorola Smartphones Confirmed to Get Discounts
  4. Flipkart Reveals Pixel 11 Series, Pixel 10a Sale Prices Ahead of Big Billion Days Sale
  5. Nothing Phone (4a), (4b) Now Available in New Variants in India: Prices
  6. Oppo Reno 16t With 200-Megapixel Camera Debuts at This Price
  7. These Xiaomi and Redmi Smartphones Could Launch Soon in China
  8. Lava Virat Curve 5G Goes on Sale in India Starting Today: Check Price
  9. Truecaller Launches Scam Checker to Detect Suspicious Links, Numbers
  1. God of War Laufey Pre-Orders Begin September 29; Digital Deluxe Edition, New Combat Details Revealed
  2. Ai+ Pulse 2 FE Launched in India Alongside Ai+ NovaTab, Nova LapTab 5G Tablets: Price, Specifications
  3. OpenAI Agents Used Multiple Workarounds to Access UN Data: Researcher
  4. Bitget Restores Bitcoin Withdrawal Services Following $388 Million Hack
  5. Nvidia Open Agent Safety Platform Launched for In-Silicon AI Agent Security With OpenShell and Sentry
  6. Zano Resumes Chain After Exploit, Restarting at Block 3,833,000
  7. Flipkart Big Billion Days Sale 2026: iPhone 17 Gets Rs. 19,901 Off, iPhone 15 Also Discounted
  8. Qualcomm Is Working on GPU Drivers That Could Improve PC Games on Android
  9. Qualcomm Could Bring Samsung’s 2nm Process to Future Snapdragon Flagships: Here’s What We Know
  10. Xiaomi 18 and Redmi K100 to Launch Soon as Phones Reportedly Appear on Certification Sites
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.