/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

GM took five years to patch privately disclosed takeover vulnerability in millions of GM cars with OnStar dashboard computers

GM Took 5 Years to Fix a Full-Takeover Hack in Millions of OnStar Cars  —  When a pair of security researchers showed they could hack a Jeep over the Internet earlier …

Wired Andy Greenberg

Context & Ripple Effects

The story lands three weeks after researchers remotely commandeered a Jeep Cherokee on the highway and forced Chrysler to ship a fix, making connected-car attack surface a front-page issue. Against that backdrop, Wired reports GM spent five years sitting on a privately disclosed full-takeover flaw affecting millions of cars with OnStar dashboard computers — while VW had separately suppressed similar research for two years about theft-enabling flaws across its brands.

The pattern matters because it shows automakers treating researcher disclosures as a liability to contain rather than a patch pipeline, even as their vehicles gain cellular-connected telematics like OnStar. GM's own response eventually shifted: months after this reporting, it partnered with HackerOne to open Detroit's first public vulnerability disclosure program.

First-order effects

  • Owners of millions of OnStar-equipped cars drove with an unpatched full-takeover vulnerability for five years after private disclosure, with no recall notice or software update reaching them.
  • GM faces reputational exposure precisely because the disclosure was private — the delay surfaced only through reporting, unlike Chrysler, whose Jeep fix at least followed a public demonstration.

Second-order effects

  • Rivals watching the Jeep, VW, and GM disclosures now weigh suppression against engagement, since each cover-up that becomes news raises the cost of the next one and invites scrutiny of every automaker's handling history.
  • Security researchers gain leverage: outlets willing to publish delayed-patch stories make silence riskier than coordinated disclosure, pushing vendors toward programs like the one GM later adopted.

Third-order effects

  • If the pattern holds, connected-car security consolidates around formal disclosure channels and mandated patch timelines rather than discretionary vendor behavior — though whether that arrives via industry norms like GM's HackerOne program or via regulation is unresolved.
  • The recurrence of the same failure mode years later — Subaru's Starlink flaws that could unlock and start millions of cars — suggests fleet-scale telematics keeps outrunning vendor patch discipline, keeping disclosure reform on the agenda.

The trend: Connected-car security is moving from quiet, multi-year vendor fixes toward public disclosure programs, driven by each new headline about delayed patches.