TechBriefly
  • Tech
  • Business
  • Crypto
  • Science
  • Geek
  • How to
  • About
    • About TechBriefly
    • Terms and Conditions
    • Privacy Policy
    • Contact Us
    • Languages
      • 中文 (Chinese)
      • Dansk
      • Deutsch
      • Español
      • English
      • Français
      • Nederlands
      • Italiano
      • 日本语 (Japanese)
      • 한국인 (Korean)
      • Norsk
      • Polski
      • Português
      • Pусский (Russian)
      • Suomalainen
      • Svenska
  • FAQ
    • Articles
No Result
View All Result
 Hot Topics:
  • Funny notes on Instagram
  • What is Snapchat planets order?
  • Best free AI art generators
  • Instagram Notes ideas
  • Elon Musk & Twitter
TechBriefly
No Result
View All Result
Home Tech Security

A Sirius XM bug causes cars to be hijacked

Hackers can also access your personal information from your car.

by Emre Çıtak
1 December 2022
in Security, Tech
Reading Time: 3 mins read
A Sirius XM bug causes cars to be hijacked
Share on FacebookShare on Twitter

Studies on self-driving cars discovered a Sirius XM bug that causes a huge security flaw.

According to recently published research, several well-known automakers, including Honda, Nissan, Infiniti, and Acura, were vulnerable to a previously unknown security flaw that might have enabled a smart hacker to take over vehicles and steal customer data using a bug in satellite radio Sirius XM.

A Sirius XM bug caused security flaws in self-driving cars
A Sirius XM bug caused security flaws in self-driving cars

Researchers claim that a bug in the Sirius XM telematics infrastructure of the car would have allowed a hacker to remotely locate a vehicle, unlock and start it, flash the lights, honk the horn, open the trunk, and access private customer information like the owner’s name, phone number, address, and vehicle specifics.

Why is the Sirius XM bug dangerous?

The majority of contemporary automobiles are essentially web-connected computers on wheels, even if you don’t own a Tesla. Cars are more handy and adaptable than ever thanks to the inflow and outflow of vehicle data or telematics, but they are also more susceptible to hacker attacks and remote hijacking.

Car manufacturers have been known to sell vehicle data to surveillance vendors, who then do strange things like sell it to government agencies, making the telematics sector a huge privacy risk.

Research claims that the Sirius XM bug in telematics infrastructure would allow hackers to access details of the car owner
Research claims that the Sirius XM bug in telematics infrastructure would allow hackers to access details of the car owner

The flaw was found by a team of security experts who were looking into problems involving significant automakers. Sam Curry, a 22-year-old cyber security specialist who is a member of the research team, said that he and his buddies were interested in the kinds of issues that would arise if they looked into the providers of so-called “telematic services” for automakers.

Sirius XM bug explained

Curry and his colleagues found an authentication flaw inside Sirius XM infrastructure after digging around in code connected to several automotive apps. The infotainment systems in most cars contain Sirius, which offers associated telematic services to most automakers.

According to Curry, Sirius XM is a common feature in vehicles, and about the flaw, he stated that:

“, bundled with the infotainment system which has the capability to perform actions on the vehicle and communicates via satellite to the internet to the SiriusXM API. It’s as if you had a cell phone connected to your vehicle and could receive and send text messages from the car telling it what to do or sharing the state of the car back to the sender.”

”In this case, they built infrastructure around the sending/receiving of this data and allowed customers to authenticate to it using some form of mobile app (whether it’s the Nissan Connected mobile app or the MyHonda app). Once the customer was logged into their account and their account had their VIN number associated to it, they could access that pipeline where they can run commands and receive data (e.g. location, speed, etc) from their vehicle.”

– Sam Curry, Cyber security specialist

Individual vehicles are sending and receiving commands and data to Sirius, which means that under the right circumstances, information might be intercepted. Curry added that a cybercriminal might have taken control of the vehicle and the data linked to the client account by taking advantage of a Sirius XM system authentication weakness.

You may check out more details and dangers about the Sirius XM bug from Sam Curry’s tweet he shared on his @samwcyo account.

More car hacking!

Earlier this year, we were able to remotely unlock, start, locate, flash, and honk any remotely connected Honda, Nissan, Infiniti, and Acura vehicles, completely unauthorized, knowing only the VIN number of the car.

Here's how we found it, and how it works: pic.twitter.com/ul3A4sT47k

— Sam Curry (@samwcyo) November 30, 2022

When Sirius XM was contacted for comment, they recognized the problem and gave the following response:

“A security researcher submitted a [bug bounty] report to Sirius XM’s Connected Vehicle Services on an authorization flaw impacting a specific telematics program. The issue was resolved within 24 hours after the report was submitted. At no point was any subscriber or other data compromised nor was any unauthorized account modified using this method.”

-Sirius XM

That covers all for the Sirius XM bug security flaw. To check if your car has Sirius XM you may check the company’s official website.

Are you interested in cyber security? Check out our other articles titled such as Cloud under attack: GoTo data breach ended up affecting LastPass or TikTok Invisible body challenge exploited by hackers from here.

 

 

 

Tags: bugfeaturedSirius XM

Related Posts

Apple iPhone 15 leaks

Apple iPhone 15 leaks: What are the latest rumors?

AI Text Classifier: OpenAI's ChatGPT detector explained

OpenAI launched AI Text Classifier for detecting AI-generated texts

Google MusicLM AI

Google MusicLM AI: Turn text to… music!

Artifact by Instagram founders

Artifact: A brand new take on news by Instagram founders

POPULAR

Soldier poet king quiz TikTok
Social Media

Soldier poet king quiz: TikTok trend explained

ai music generator open ai jukebox
AI

AI music generators take on a whole new dimension with Open AI Jukebox

ChatGPT is at capacity right now: Too many requests in 1 hour try again later (Fixed)
How to

Too many requests in 1 hour try again later (Fixed): ChatGPT is at capacity right now

Bane of Dragons ESO
How to

Bane of Dragons ESO: How to complete the quest?

What is Snapchat planets order?
How to

What is Snapchat planets order?

Witcher 3 manual save not working
How to

Witcher 3 manual save not working: How to fix it?

Answering the most common questions about the Instagram collab feature
How to

Answering the most common questions about the Instagram collab feature

Division 2 crashing: How to fix it (2023)?
How to

How to fix Division 2 if it keeps crashing in 2023?

Fortnite Rarity Check Augment
How to

Fortnite Rarity Check Augment explained

How to hide retakes on BeReal?
How to

How to hide retakes on BeReal?

RSS Digital Report

  • Back door marketing: What is it?
  • What is outbound marketing: Complete Guide
  • Online marketing for real estate: Tips and tricks
  • Top 5 SEO reporting software tools
  • Tips and tools for DIY digital marketing
  • Rundown of Uber’s marketing strategy
  • Tips and tricks for chatbot marketing
  • The Forex movement in 2023 vs crypto
  • How big companies are using AI in marketing?
  • Get the best features of public and private platforms with hybrid blockchains

RSS Latest from LeaderGamer

  • The Sims developers reveal new information about Project Rene
  • New Street Fighter game revealed
  • Ubisoft announces The Crew Motorfest
  • Amazon may have bought the Tomb Raider IP rights
  • DLSS 3 and Reflex support came with Cyberpunk 2077 update
  • How to get Destiny 2 Quicksilver Storm?
  • Star Wars Jedi Survivor release date, story, gameplay
  • Wordle TR 2 Şubat 2023 günün cevabı
  • New Nintendo Direct could be in February 2023
  • Avatar Generations is out with a new trailer
TechBriefly

© 2021 TechBriefly is a Linkmedya brand.

  • Tech
  • Business
  • Science
  • Geek
  • How to
  • About
  • Privacy
  • Terms
  • Contact
  • LeaderGamer
  • FAQ

Follow Us

No Result
View All Result
  • Tech
  • Business
  • Crypto
  • Science
  • Geek
  • How to
  • About
    • About TechBriefly
    • Terms and Conditions
    • Privacy Policy
    • Contact Us
    • Languages
      • 中文 (Chinese)
      • Dansk
      • Deutsch
      • Español
      • English
      • Français
      • Nederlands
      • Italiano
      • 日本语 (Japanese)
      • 한국인 (Korean)
      • Norsk
      • Polski
      • Português
      • Pусский (Russian)
      • Suomalainen
      • Svenska
  • FAQ
    • Articles