By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Hackers Could Have Remotely Controlled Kia Cars Using Only License Plates
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Hackers Could Have Remotely Controlled Kia Cars Using Only License Plates
Tech News

Hackers Could Have Remotely Controlled Kia Cars Using Only License Plates

By Viral Trending Content 4 Min Read
Share
SHARE

Sep 26, 2024Ravie LakshmananAutomotive Industry / Technology

Remotely Controlled Kia Cars

Cybersecurity researchers have disclosed a set of now patched vulnerabilities in Kia vehicles that, if successfully exploited, could have allowed remote control over key functions simply by using only a license plate.

“These attacks could be executed remotely on any hardware-equipped vehicle in about 30 seconds, regardless of whether it had an active Kia Connect subscription,” security researchers Neiko Rivera, Sam Curry, Justin Rhinehart, and Ian Carroll said.

The issues impact almost all vehicles made after 2013, even letting attackers covertly gain access to sensitive information including the victim’s name, phone number, email address, and physical address.

Cybersecurity

Essentially, this could then be abused by the adversary to add themselves as an “invisible” second user on the car without the owner’s knowledge.

The crux of the research is that the issues exploit the Kia dealership infrastructure (“kiaconnect.kdealer[.]com”) used for vehicle activations to register for a fake account via an HTTP request and then generate access tokens.

The token is subsequently used in conjunction with another HTTP request to a dealer APIGW endpoint and the vehicle identification number (VIN) of a car to obtain the vehicle owner’s name, phone number, and email address.

What’s more, the researchers found that it’s possible to gain access to a victim’s vehicle by as trivially as issuing four HTTP requests, and ultimately executing internet-to-vehicle commands –

  • Generate the dealer token and retrieve the “token” header from the HTTP response using the aforementioned method
  • Fetch victim’s email address and phone number
  • Modify owner’s previous access using leaked email address and VIN number to add the attacker as the primary account holder
  • Add attacker to victim vehicle by adding an email address under their control as the primary owner of the vehicle, thereby allowing for running arbitrary commands

“From the victim’s side, there was no notification that their vehicle had been accessed nor their access permissions modified,” the researchers pointed out.

Cybersecurity

“An attacker could resolve someone’s license plate, enter their VIN through the API, then track them passively and send active commands like unlock, start, or honk.”

Remotely Controlled Kia Cars

In a hypothetical attack scenario, a bad actor could enter the license plate of a Kia vehicle in a custom dashboard, retrieve the victim’s information, and then execute commands on the vehicle after around 30 seconds.

Following responsible disclosure in June 2024, the flaws were addressed by Kia as of August 14, 2024. There is no evidence that these vulnerabilities were ever exploited in the wild.

“Cars will continue to have vulnerabilities, because in the same way that Meta could introduce a code change which would allow someone to take over your Facebook account, car manufacturers could do the same for your vehicle,” the researchers said.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

Factor Meal Delivery Promo: Free $200 Withings Body-Scan Scale

IBM warns of critical API Connect auth bypass vulnerability

IBM warns of critical API Connect auth bypass vulnerability

U.S. Treasury Lifts Sanctions on Three Individuals Linked to Intellexa and Predator Spyware

Drone service to deliver automated defibrillators

TAGGED: Automotive Industry, car hacking, Cyber Security, Cybersecurity, data privacy, hacking, Internet, Smart Car, Technology, Vehicle Security
Share This Article
Facebook Twitter Copy Link
Previous Article Johnson and Solanke on target as 10-man Spurs ease past wasteful Qarabag
Next Article Sebi chief Buch hopes corp bond mkt grows as rapidly as equities
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Factor Meal Delivery Promo: Free $200 Withings Body-Scan Scale
Tech News
IBM warns of critical API Connect auth bypass vulnerability
Tech News
IBM warns of critical API Connect auth bypass vulnerability
Tech News
Pi Network suspends wallet payment requests after scammers drain millions
Crypto
U.S. Treasury Lifts Sanctions on Three Individuals Linked to Intellexa and Predator Spyware
Tech News
Chelsea’s inconsistencies are a troubling mess after Bournemouth draw – opinion
Sports
BitMine Loads Up On $98 Million Worth Of ETH As 2025 Winds Down
Crypto

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Factor Meal Delivery Promo: Free $200 Withings Body-Scan Scale

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Factor Meal Delivery Promo: Free $200 Withings Body-Scan Scale
December 31, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?