GM took five years to patch privately disclosed takeover vulnerability in millions of GM cars with OnStar dashboard computers
GM Took 5 Years to Fix a Full-Takeover Hack in Millions of OnStar Cars — When a pair of security researchers showed they could hack a Jeep over the Internet earlier …
Context & Ripple Effects
The story lands three weeks after researchers remotely commandeered a Jeep Cherokee on the highway and forced Chrysler to ship a fix, making connected-car attack surface a front-page issue. Against that backdrop, Wired reports GM spent five years sitting on a privately disclosed full-takeover flaw affecting millions of cars with OnStar dashboard computers — while VW had separately suppressed similar research for two years about theft-enabling flaws across its brands.
The pattern matters because it shows automakers treating researcher disclosures as a liability to contain rather than a patch pipeline, even as their vehicles gain cellular-connected telematics like OnStar. GM's own response eventually shifted: months after this reporting, it partnered with HackerOne to open Detroit's first public vulnerability disclosure program.
First-order effects
- Owners of millions of OnStar-equipped cars drove with an unpatched full-takeover vulnerability for five years after private disclosure, with no recall notice or software update reaching them.
- GM faces reputational exposure precisely because the disclosure was private — the delay surfaced only through reporting, unlike Chrysler, whose Jeep fix at least followed a public demonstration.
Second-order effects
- Rivals watching the Jeep, VW, and GM disclosures now weigh suppression against engagement, since each cover-up that becomes news raises the cost of the next one and invites scrutiny of every automaker's handling history.
- Security researchers gain leverage: outlets willing to publish delayed-patch stories make silence riskier than coordinated disclosure, pushing vendors toward programs like the one GM later adopted.
Third-order effects
- If the pattern holds, connected-car security consolidates around formal disclosure channels and mandated patch timelines rather than discretionary vendor behavior — though whether that arrives via industry norms like GM's HackerOne program or via regulation is unresolved.
- The recurrence of the same failure mode years later — Subaru's Starlink flaws that could unlock and start millions of cars — suggests fleet-scale telematics keeps outrunning vendor patch discipline, keeping disclosure reform on the agenda.
The trend: Connected-car security is moving from quiet, multi-year vendor fixes toward public disclosure programs, driven by each new headline about delayed patches.