technologyliberal
Car Tracking Flaws Revealed in Subaru Systems
USAThursday, January 23, 2025
Subaru acknowledged the issue and stated that the vulnerability was immediately closed. They also confirmed that employees with relevant jobs can access location data. This access is meant to help in cases like notifying first responders during collisions.
Curry and Shah found the flaws while exploring the administrative domain SubaruCS. com. They could reset employee passwords just by guessing email addresses. This allowed them to take over any employee's account and look up any Subaru owner's details. Within seconds, they could control features like unlocking cars, honking horns, and starting ignitions remotely.
The researchers emphasized that multiple systemic failures led to this security breach. They found it concerning that even with the patch, Subaru employees still have extensive access to location data.
Actions
flag content