Реклама партнера — Название партнёра
UNIT.City — місце, де люди працюють... КРАЩЕ! Обирай свій простір просто зараз 👉

Bluetooth vulnerability allows hackers to connect to Mercedes, Volkswagen and Skoda cars: risk to contacts, GPS and conversations

A number of critical vulnerabilities have been discovered in the BlueSDK Bluetooth stack, which is used in multimedia systems of popular cars. Potentially, attackers can listen to conversations, gain access to contacts and geolocation. Owners of Mercedes, Volkswagen, Skoda and, probably, other brands are at risk.

Leave a comment
Bluetooth vulnerability allows hackers to connect to Mercedes, Volkswagen and Skoda cars: risk to contacts, GPS and conversations

A number of critical vulnerabilities have been discovered in the BlueSDK Bluetooth stack, which is used in multimedia systems of popular cars. Potentially, attackers can listen to conversations, gain access to contacts and geolocation. Owners of Mercedes, Volkswagen, Skoda and, probably, other brands are at risk.

According to BleepingComputer, researchers at PCA Cyber ​​Security have discovered four vulnerabilities in the BlueSDK Bluetooth stack, identified as CVE-2024-45434, CVE-2024-45431, CVE-2024-45433, and CVE-2024-45432. Together, they form an exploit called PerfektBlue, which allows for remote code execution (RCE) attacks.

In theory, an attacker could connect to a car’s multimedia system via Bluetooth if the victim agrees to the connection (or it happens automatically). This would then give access to sensitive information from the connected devices, such as contacts, audio, GPS data, etc.

Researchers warned the stack developer (OpenSynergy) back in June 2024. The patch was released in September, but automakers have yet to implement it. According to PCA Cyber ​​Security, no manufacturer has done so yet. The only exception was Volkswagen, which launched an internal investigation and published a list of conditions under which the vulnerability could be exploited:

  • the attacker must be within a radius of 5-7 meters from the car;
  • the car ignition must be on;
  • the multimedia system must be in pairing mode;
  • the user must manually confirm the device connection.

The BlueSDK stack is used in many industries, including the automotive industry. Often, such components are implemented without understanding the real level of their security, which creates risks for both drivers and passengers. With the growth of connected cars, the issue of wireless security is becoming a priority. Given the passivity of most automakers, users should be careful about Bluetooth connections in their cars.

We previously wrote about how Android users are at risk of being redirected to fraudulent websites or unknowingly running commands in apps due to a newly discovered vulnerability in the notification system. Everything looks like a normal message with a link, but in reality it opens a completely different URL or activates a hidden action.

A resident of Aitiva found a technological solution to combat loud music from neighbors by hacking their Bluetooth speakers
A resident of Aitiva found a technological solution to combat loud music from neighbors by hacking their Bluetooth speakers
On the topic
A resident of Aitiva found a technological solution to combat loud music from neighbors by hacking their Bluetooth speakers
Developers announced Bluetooth v6.0 with improved capabilities
Developers announced Bluetooth v6.0 with improved capabilities
On the topic
Developers announced Bluetooth v6.0 with improved capabilities
Google allowed a vulnerability that allowed it to determine any linked phone number in less than 20 minutes
Google allowed a vulnerability that allowed it to identify any linked phone number in less than 20 minutes
On the topic
Google allowed a vulnerability that allowed it to identify any linked phone number in less than 20 minutes
Read the country's main IT news in our Telegram
Read the country’s main IT news in our Telegram
On the topic
Read the country’s main IT news in our Telegram

Have important news to share? Message our Telegram bot

Key events and useful links in our Telegram channel

Discussion
No comments yet.