Researchers find API security flaws in almost 20 car manufacturers' systems that could let hackers unlock, start, and track cars, plus access customers' data
Bill Toulas / BleepingComputer :
Context & Ripple Effects
Car hacking has been migrating inward for a decade: from the indefensible CAN protocol vulnerability at the vehicle's core, to immobilizer encryption flaws in Toyota, Hyundai, and Kia keys, to a radio amplification attack spanning 24 models from 19 manufacturers. Each wave moved the attack surface further from the car itself.
This report completes that migration: the flaw isn't in a fob or a bus, it's in the cloud APIs that let apps remotely unlock, start, and track vehicles — the same class of web-portal weakness researchers demonstrated against Kia's dealer portal, which exposed millions of cars. With nearly 20 manufacturers implicated at once, this is no longer one vendor's bug but an industry-wide design problem.
First-order effects
- Nearly 20 manufacturers face emergency API audits and patches, since any unauthenticated endpoint can hand strangers remote unlock, ignition, and location access to customer vehicles.
- Owners of affected brands are exposed right now — both physically (their car can be opened and started by someone else) and financially, through theft of personal data held in the same systems.
Second-order effects
- The Kia portal disclosure set the template of researcher-report-then-fix; with this many brands hit simultaneously, automakers will be pushed toward shared security standards and third-party penetration testing rather than per-company quiet fixes.
- Fleet buyers and insurers gain leverage to demand API security attestations before deploying connected-vehicle services, making remote-control architecture a procurement criterion rather than an afterthought.
Third-order effects
- If every new connectivity feature ships with a remotely exploitable counterpart, regulators — who flagged wireless vehicle risks as far back as the 2015 Senate report — are positioned to mandate secure-by-design requirements for telematics APIs, not just crash-test-style physical safety.
- The industry structure shifts so that whoever operates the cloud layer (automaker or software supplier) bears liability for vehicle security, potentially forcing consolidation of telematics platforms under fewer, better-audited providers.
The trend: Connected-car security is shifting from hardware exploits like key-fob relay and CAN-bus attacks to cloud API weaknesses, where a single flawed endpoint scales to millions of vehicles across many brands.