Major security flaws found in Mercedes, Ferrari and other top luxury cars

Smart Car
(Image credit: 123RF)

Major security flaws have been found in Mercedes, Ferrari, and other top luxury cars which could have allowed threat actors to steal the owners’ personally identifiable information, track their vehicles, and in some cases - even unlock and start the cars.

Almost two-dozen car brands were affected by the flaws, including top brands such as BMW, Roll Royce, Mercedes-Benz, Ferrari, Porsche, Jaguar, Land Rover, Ford, KIA, Honda, Infiniti, Nissan, Acura, Hyundai, Toyota, and Genesis. 

Besides car manufacturers, car technology makers Spireon and Reviver were also impacted, as well as SiriusXM Connected Vehicle Services.

Access to private data

The flaws were discovered by cybersecurity researcher Sam Curry who has a history of discovering security flaws in connected cars. In early December 2022, he discovered a flaw in SiriusXM Connected Vehicle Services that enabled threat actors to access connected vehicles.

In this case, different manufacturers had different vulnerabilities. BMW and Mercedes-Benz have had a flawed Single-Sign-On (SSO) feature that allowed threat actors to access internal systems, giving them access to GitHub instances, private chats, servers, AWS instances, and more. 

With BMW, potential attackers could have gotten access to internal dealer portals, car VIN numbers, as well as sales documents with sensitive owner details.

Besides the two major brands, owners of KIA, Honda, Infiniti, Nissan, Acura, Mercedes-Benz, Hyundai, Genesis, BMW, Roll Royce, Ferrari, Ford, Porsche, and Toyota cars, could have had their personally identifiable information (PII) leaked. 

Ferrari was also heavily affected, as the SSO flaw allowed threat actors to access, modify, or delete, any Ferrari customer account. They could have even set themselves as car owners. With Porsche, flaws in its telematic systems allowed threat actors to pinpoint the exact location of the cars, and even send commands to the vehicles.

All of the impacted vendors were notified of the findings, and have since fixed the flaws.

GPS vehicle tracking provider Spireon, allegedly used in more than 15 million vehicles, carried a flaw which, among other things, allowed for threat actors to unlock the cars, start the engine, or disable the starter. 

To protect against such flaws in the future, researchers suggest vehicle owners store as little personal information in vehicles and mobile companion apps as possible.

Via: BleepingComputer

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Subaru Starlink
Hackers expose serious Subaru security flaws that allow them to remotely start cars
Volkswagen Lane Keep
Over 800,000 electric car owners and drivers may have had private info exposed online
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
Major ransomware attack sees Tata Technologies hit - 1.4TB dataset with over 730,000 files allegedly stolen
Password
Millions of airline customers possibly affected by OAuth security flaw
Image depicting a hand on a scanner
Top Uber rival leaks user and driver data online
Illustration of a thief escaping with a white fingerprint
5 massive privacy scandals that rocked the world – and made millions of victims
Latest in Security
An American flag flying outside the US Capitol building against a blue sky
The FCC is creating a security council to bolster US defenses against cyberattacks
Image depicting hands typing on a keyboard, with phishing hooks holding files, passwords and credit cards.
Microsoft warns about a new phishing campaign impersonating Booking.com
Ransomware
Microsoft uncovers sleuthy new XCSSET MacOS malware campaign
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Meta warns of worrying security flaw hitting open source type software
Hand holding smartphone and scan fingerprint biometric identity for unlock her mobile phone
Biometrics add another layer of security to passwordless authentication
Data leak
Hacked Tata Technologies data leaked by ransomware gang
Latest in News
Google Gemini Flash 2.0 Images
I tried Gemini's new AI image generation tool - here are 5 ways to get the best art from Google's Flash 2.0
An image of the Samsung Galaxy S25 Ultra from a hands-on event
Samsung Galaxy S26 Ultra could resurrect an intriguing camera feature
Eurocom Raptor X18
At $15,000, this massive 256GB RAM laptop makes Apple's MacBook Pro look affordable, tiny and very, very slow
Cristin Milioti in Black Mirror season 7
Netflix launches trailer for Black Mirror season 7, giving us a look at its first-ever sequel episode and an unexpected returning character
A graphic of the PC Gaming Show
Get ready for a bounty of PC games on June 8, as the PC Gaming show is back
A close up of The Daily podcast from Pocket Casts' web page
‘Podcasting shouldn’t be locked behind walled gardens’: Pocket Casts slams Spotify and makes its web player free to all