Hackers expose serious Subaru security flaws that allow them to remotely start cars




  • Two hackers exposed serious security flaws in a 2023 Subaru Impreza
  • Vulnerabilities in a Subaru web portal allowed the pair remote access
  • Similar issues could affect a number of major automotive brands

A pair of hackers have revealed how they remotely took control of a Subaru Impreza, thanks to a serious security flaw in Subaru’s Starlink-connected infotainment system.

Sam Curry and Shubham Shah (the latter was working remotely) managed to leverage vulnerabilities in a Subaru web portal that allowed the pair to take control of Curry’s mother’s vehicle, including the ability to unlock the car, honk its horn and start its ignition with any smartphone or computer they chose, according to a report by Wired.

Curry revealed his tactics in a video and a lengthy blog post, which went into detail about how he was able to enter said web portal and hijack a Subaru employee’s account by simply resetting a password, which would then allow him to tap into millions of Subaru vehicles remotely with a customer’s name, registration number, or zip code.

The prolific hacker claims that it was possible to retrieve at least a year’s worth of location history from his mother’s car, including accurately mapped details of exactly where she had been, down to the exact parking space his mother parked in every time she went to church.

Subaru claims that once the pair had notified the company, it set to work fixing and patching the vulnerability in its employee portal while adding that it’s important for the company to collect location data to help its employees assist with emergencies and to help track stolen vehicles.

However, Curry and the wider hacking community say that there is little need for manufacturers to collect years’ worth of customer location data. Further, he believes that the sort of web vulnerabilities aren’t just limited to Subaru – similarly serious hackable bugs exist in the web tools of Acura, Genesis, Honda, Hyundai, Infiniti, Kia, Toyota, and many others.

Analysis: The connected car is a data privacy nightmare

Google Gemini Mercedes

(Image credit: Google)

Earlier this week, security researchers from Kaspersky published a report that revealed how the team had found 13 vulnerabilities in the first-generation Mercedes-Benz User Experience (MBUX) infotainment system.

These flaws would allow hackers to potentially steal data and disable anti-theft protections should they be able to get physical access to the vehicle. Mercedes-Benz said that it had been aware of Kaspersky’s findings since 2022 and that the vulnerabilities had been patched.

Moreover, the German company pointed out that the head unit of its infotainment system had to be removed and opened for a successful hack to take place – making it slightly less worrying than the issues found with Subaru’s vehicles.

That said, many industry insiders and cybersecurity experts have warned that modern connected car poses a serious security risk for a long time, with Mozilla going so far as to say “modern cars are a privacy nightmare” in a report released in 2023.

Mozilla found that many cars collect more data than they need to, making it near impossible for users to opt out of the harvesting and then go on to sell this information to third parties without the user knowing.

Aside from being a massive invasion of privacy, vehicles equipped with cameras, microphones, and a constant connection to the internet now offer a plethora of ways for potential hackers to gain remote access.

Automotive manufacturers are clearly aware of this and many have created standalone software divisions to help deal with the threat, but it’s clear that there is still work to do.

You might also like

Have questions? Need answers?

If you have any IT related issues, we have the solution for you. Whether you need long-term Mac and PC support or an urgent fix, don't hesitate and get in touch.

Contact us now!

Over 320 Satisfied Customers

I just wanted to say thank you for the visit today from SupportPlan. The engineer picked up many issues that we had outstanding and was professional and tireless! Really grateful for all his support and expertise today.

Beth, Operations Manager

SupportPlan has been a highly valued supplier to APR Communications, supporting our luxury PR agency from 1997 until 2018 when the company merged to become ANM.

We cannot recommend SupportPlan more highly.  Not only have SupportPlan provided an impeccable service; they have also been a true partner of the agency providing excellent counsel re our IT requirements and valuable cost-saving advice.

The team are very responsible and always go the extra mile in providing technical solutions in a user-friendly manner.

We wish Lance and the SupportPlan team our best and have been honoured to work with them.

Annabel McAvoy, Managing Partner, APR Communications LLP

All unforeseen problems were handled smoothly and calmly with the expertise of the engineers…[SupportPlan] sold me solutions and not technology.

Reginald Thompson, Conran Design Group Ltd

SupportPlan are fast, efficient, friendly and very knowledgeable. They have resolved any problems I have thrown their way and in quick time.  I would recommend them to any company.

Design Manager, Colliers International

I rely on SupportPlan. Even though I’m able to carry out certain tasks, it’s reassuring to know that SupportPlan is on the other end of the phone if I need them for back up.

Neil Hickford, Four IV Design

I work in a very busy marketing team. Knowing that SupportPlan are there to help us, in case of any problems has always been reassuring. They proved it one day when my Mac broke down as I was facing a tough deadline. Not only did SupportPlan swiftly replace the faulty computer, but their engineer also transferred all my files to the new Mac, enabling me to get back to work right away.

Claudia Mansaray, Marketing Communications Executive, Alzheimer's Society

I had the opportunity to work with your engineer via telephone today. I was so impressed with his helpfulness, knowledge and professionalism that I felt that I should send this email complement. Who ever hired him made the right decision. I will certainly be recommending your company to any other company I work with.

John McCrudden, MSc MCSE ACTC JNCIS-ER, "IT Infrastructure Specialist", Mitie Business Services

SupportPlan’s engineers have the knack for solving problems quickly by asking jargon-free questions that make a user feel like an IT expert.

Christine Holdforth, Manager, Corporate Publicity and Design Studio, Department of Education and Skills

SupportPlan is unusual in that the ‘top man’ is much more hands on with his clients than in other comparable organisations and is happy to step in when required. The engineers are responsive in a crisis and devote themselves to solving the problem efficiently.

Irena St John-Brooks, Managing Director, Pension Publications Ltd

SupportPlan are a rare breed in that they genuinely understand creative agencies and how we use IT in the business. They provide all our day-to-day IT support in a seamless and proactive way as well as advising us at a strategic level.

Financial Director, Salter Baxter

We were very impressed not only by the promptness of response but also by the consistency for the support…our Mac users were able to build up a strong working relationship with the regular team of experts from SupportPlan.

Richard Swann, IT Manager, Institute of Directors

I thoroughly recommend SupportPlan for whatever creative IT needs you may have…their expert knowledge is worth their weight in gold, let alone the service and range of services they back this up with. They are and always will be constant to my working life, as they have never let me down.

Neil Carter, Studio Manager, Penna Plc.

It’s reassuring to know that I have the breadth of skills of the SupportPlan team to back me up when I need them.

Gareth Perry, Group IT Manager, Eaglemoss

I have no hesitation recommending SupportPlan. They have maintained our computers for 12 years and they have ensured that any problems are resolved on the same day so we experienced as little down time during working hours. Their technicians are extremely knowledgeable and are always polite and helpful.

Accreditations


It’s not just our customers that recognise our hard work, we are accredited by Apple, Microsoft, Dell, HP, VMWare, Juniper, Kerio, Archiware P5, as well as many other manufacturers.

Our clients range from corporate giants, to hundreds of smaller businesses, many of whom rely on us to be their virtual IT department. They know we will never compromise on providing the right person for the right IT challenge and that’s why we’re the obvious first port of call when IT support is needed.

Bitwarden Certified Reseller
Google Workspace Essentials
IONOS Agency Partner
Dropbox Certified Administrator
Dropbox Certified Seller
Barracuda
Draytek
Mimecast Partners
Altaro Partners
Sophos Silver Partner
COMPTIA Network +
Cyber Essentials Certified – Security
silver-small-midmarket-cloud-solutions
Apple Certified Support Professional
Adobe Accredited Sales Specialist: Creative Cloud for teams
Adobe Certified Sales Professional: Volume Licensing
Adobe Certified Sales Professional: Acrobat XI
Adobe Certified Sales Professional: Creative Suite 6
Microsoft Certified Technology Specialist
CompTIA Certified
Dell PartnerDirect Registered
VMWare Certified Professional 4
Microsoft Small Business Specialist
Kerio Certified Partner
Apple Certified System Administrator
Apple Consultants Network
^Back to top