Researchers have identified a critical security flaw in aftermarket alarm systems installed by dealerships across millions of US vehicles. The devices can be hacked to unlock cars, enable tracking, and disable engine functionality.
Security researchers have discovered that alarm systems covertly installed in millions of vehicles sold by US dealerships contain vulnerabilities that allow remote attackers to compromise vehicle security and safety.
The alarms were installed by dealerships without buyer consent or awareness in many cases. Even customers who explicitly declined the devices found them operational in their vehicles, buried in electrical systems and difficult to locate or remove.
According to the research, hackers exploiting these vulnerabilities could:
- Unlock vehicle doors remotely
- Activate GPS tracking to monitor location
- Disable engines, effectively immobilizing cars
- Bypass factory security systems
The flaws stem from weak security protocols in the alarm systems' wireless communication and lack of encryption on critical functions. Researchers identified multiple entry points that require minimal technical expertise to exploit.
Affected vehicles span multiple years and manufacturers, though specific models have not been publicly disclosed to prevent immediate widespread exploitation. The vulnerability impacts both luxury and standard vehicle segments.
Dealerships have been contacted about deploying patches and firmware updates to address the security gaps. However, widespread implementation remains unclear given the distributed nature of dealership networks and varying technical capabilities.
Vehicle owners are advised to contact their dealerships immediately to determine if their cars contain these systems and request patches. Those unable to locate the devices should request professional inspection and removal if they choose not to keep the alarm functionality.
Manufacturers are being pressured to implement stronger security standards for aftermarket systems and improve oversight of dealership installation practices. The incident highlights broader concerns about connected vehicle security as cars become increasingly networked.
Iran's Islamic Revolutionary Guard Corps (IRGC) claimed it destroyed Amazon's central data infrastructure in Bahrain using cruise missiles. Amazon has not commented on the alleged attack.
The UK government has abandoned its digital ID card program following widespread public opposition. The decision clears the way for a tax cut initiative aimed at easing the cost of living crisis.
A breach of AI music generator Suno exposed personal data from 55 million users, according to Have I Been Pwned. Stolen information includes names, phone numbers, and physical addresses.
Security researchers discovered that more than 12% of applications marketed to US military personnel contain code from China and Russia. The findings raise concerns about potential surveillance and data compromise risks.