Cybersecurity Flaw Could Leave Millions of Vehicles Exposed
Key points
Slate’s electric pickup starts at $24,950 and offers 205 miles of range.
Its modular design allows owners to easily upgrade and customize the vehicle with hardware.
The electric truck features NACS charging capability and will begin shipping in late 2026.
Cybersecurity researchers have uncovered a vulnerability in a Bluetooth-controlled security system installed by dealerships on more than 2 million vehicles sold since 2017. The flaw, which affects vehicles from several major brands including Honda, Toyota, Mazda, Ford, and Jeep, could allow an attacker using an off-the-shelf smartphone to remotely unlock an affected vehicle.
Although researchers say they are not aware of the vulnerability being actively exploited, they warn it could make vehicle theft easier by allowing thieves to access the cabin before using key-cloning tools to steal the car. The system’s vendor has released a software update, and owners are encouraged to check whether their vehicle is equipped with the affected dealer-installed system and install the update if needed.
Transcript
00:00:00 I lead a team of cybersecurity researchers and we discovered that if you have this sticker on your car, you’re likely to be vulnerable to an attacker taking control of it using only an off-the-shelf smartphone. I’m Aaron Schulman, an associate professor of computer science and engineering at UC San Diego. This threat comes from a vulnerability that we discovered in a
00:00:20 Bluetooth controlled security system that’s installed in cars sold by many dealerships across the southwestern United States. Since 2017, we estimate it’s been installed in over 2 million cars sold by dealers of many popular brands including Honda, Toyota, Mazda, Ford, and Jeep. With a malicious smartphone app, we found that an attacker can authenticate
00:00:44 with any car that has this system. They can unlock the car’s doors even when the owner is away. So, we’re not aware of anyone actively exploiting this vulnerability, but to prevent future threats, our team notified the vendor and they developed an update that you can install to mitigate the threat. Check under your dashboard. If you see this button, your
00:01:05 car likely has the vulnerable system installed and this update needs to be installed even if you’re a vehicle owner who didn’t activate the system when you bought your car at the dealership because unfortunately, we found that an attacker can still successfully re-enable it. Another reason to update is that we found this system may make it a lot
00:01:27 easier and more stealthy for car thieves to steal cars. The attacker will be able to use the vulnerable system to unlock the car’s doors and get inside the car. Once they’re inside, car thieves can use locksmith key cloning tools to extract the key from your car’s computer and then use it to start your car’s ignition and unfortunately then drive away.