Sirius XM flaw could’ve let hackers remotely unlock and start cars

TL;DR

While telematics systems obtain data about your car’s GPS location, speed, turn-by-turn navigation, and maintenance requirements, certain infotainment setups might track call logs, voice commands, text messages, and more.In a statement to Gizmodo, Curry says Sirius XM “built infrastructure around the sending/receiving of this data and allowed customers to authenticate to it using some form of mobile app,” like MyHonda or Nissan Connected.Users can log into their accounts on these apps, which are linked to their vehicle’s VIN number, to execute commands and obtain information about their cars.It’s this system that could give bad actors access to someone’s car, Curry explains, as Sirius XM uses the VIN number linked with a person’s account to relay information and commands between the app and its servers.In a statement to The Verge, company spokesperson Lynnsey Ross said the vulnerability “was resolved within 24 hours after the report was submitted,” adding that “at no point was any subscriber or other data compromised nor was any unauthorized account modified using this method.”Separately, Curry uncovered another flaw within the MyHyundai and MyGenesis apps that could also potentially let hackers remotely hijack a vehicle, but says he worked with the automaker to fix the issue."

Like summarized versions? Support us on Patreon!