Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

New vulnerability lets attackers hijack Chrysler vehicles over the web
The Verge ^ | July 21, 2015 10:57 am | By Russell Brandom

Posted on 07/21/2015 1:24:13 PM PDT by Swordmaker

A new vulnerability in the Uconnect system gives attackers frightening remote powers over Chrysler vehicles, revealed in a Wired exclusive report. In a live demo, attackers used the vulnerability to cut out a Jeep Cherokee's transmission and brakes and, when the car is in reverse, commandeer the steering wheel — all without physical access to the vehicle. "This might be the kind of software bug most likely to kill someone," said Charlie Miller, one of the researchers behind the exploit. The full vulnerability will be presented next month at Defcon, although the researchers plan to withhold crucial details so that the bug cannot be exploited at scale.

Chrysler's UConnect system uses Sprint's cellular network for connectivity, so researchers were able to remotely locate cars by scanning for devices using that particular spectrum band. Chrysler has been including UConnect in cars since late 2013, and any cars that use the system are likely to be vulnerable to the attack. There's no apparent firewall, so once attackers have located the device's IP, they can deploy previously developed exploits to rewrite Uconnect's firmware and control the car as if they had physical access. The result is that once an attacker has a car's IP address, she can target it from anywhere in the country.

The good news for Chrysler drivers is, there's already a patch — but it probably hasn't reached your car yet. Chrysler released a patch on the 16th, but it has to be installed manually, either by a dealership mechanic or manually via USB. It can be downloaded here. The vulnerability has also inspired government action, as a new automotive security bill is being introduced in the Senate alongside the report.

7/21 11:48am ET: This article previously referred to the test vehicle as a Jeep Grand Cherokee. The correct name is simply Jeep Cherokee.


TOPICS: Business/Economy; Computers/Internet; Travel
KEYWORDS: chrysler; sprint; uconnect; vehicleshacked
Navigation: use the links below to view more comments.
first previous 1-2021 last
To: Yo-Yo

Ridiculous! If someone can’t park, they shouldn’t drive.


21 posted on 07/21/2015 2:19:42 PM PDT by bicyclerepair (Ft. Lauderdale FL (zombie land). TERM LIMITS ... TERM LIMITS)
[ Post Reply | Private Reply | To 16 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson