Hackers remotely gain partial control of a Jeep Cherokee on the highway using vulnerability found in thousands of Chrysler cars, SUVs, and trucks
Hackers Remotely Kill a Jeep on the Highway—With Me in It — I was driving 70 mph on the edge of downtown St. Louis when the exploit began to take hold.
Context & Ripple Effects
The demo is the proof case for everything that followed in this coverage cycle: researchers driving a Jeep Cherokee at 70 mph near St. Louis while attackers reached it over its cellular-connected UConnect head unit, steering the exploit from brakes to transmission. Within days Chrysler issued what the corpus records as a 1.4-million-vehicle recall, but the patch arrived as software owners had to install manually — no over-the-air path for the fleet it needed to protect.
First-order effects
- Chrysler's recall covers 1.4 million cars, SUVs, and trucks sharing the vulnerable UConnect system, and owners must apply the fix themselves or visit a dealer — an update process that guarantees slow adoption across the exposed fleet.
- NHTSA's follow-on probe widened the blast radius beyond one automaker: the investigation into infotainment supplier Harman Kardon flagged up to 2.8 million vehicles across multiple manufacturers using similar systems.
Second-order effects
- The disclosure forced every connected-car program to treat its head-unit supplier as a security perimeter: NHTSA probing Harman Kardon shifts liability upstream toward tier-one vendors whose software ships in millions of vehicles they don't brand.
- GM's parallel exposure — a privately disclosed OnStar takeover vulnerability that sat unpatched for five years in millions of cars — shows the same class of remote-access defect predating this incident, meaning other OEMs now face pressure to disclose and fix stale vulnerabilities before researchers force the issue publicly.
Third-order effects
- If the pattern holds, physical recalls give way to regulatory mandates for over-the-air update capability as a safety requirement, not a convenience feature — the Corvette brake hack delivered through an insurance dongle, patched via OTA updates, sketches both halves of that future.
- The longer arc runs from vehicle-level fixes to supply-chain accountability: when one infotainment vendor can expose 2.8 million vehicles across brands, certification regimes will have to audit component suppliers the way they audit automakers.
The trend: Connected cars are turning automotive security from a per-model engineering problem into a regulator-supervised supply-chain problem, with over-the-air update capability becoming the dividing line between recallable and resilient fleets.