/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researchers detail Subaru's now-fixed web vulnerabilities that would've let them unlock and start millions of Subarus via Starlink in the US, Canada, and Japan

Now-fixed web bugs allowed hackers to remotely unlock and start millions of Subarus.  More disturbingly, they could also access …

Wired Andy Greenberg

Context & Ripple Effects

This is another case of connected-vehicle access being exposed through a web service rather than a physical break-in. A 2023 study had already identified API weaknesses across nearly 20 automakers that could expose remote lock, start, and tracking functions.

The Subaru disclosure also follows a recent Kia portal flaw with similar remote-control implications. Together, the cases make the security of manufacturer web portals and their authorization flows central to vehicle safety and customer trust.

First-order effects

  • Subaru’s fixes remove the reported path for attackers to remotely unlock and start affected vehicles in the US, Canada, and Japan.
  • The disclosure puts Subaru’s remote-access systems under sharper scrutiny, particularly the web controls that connect customer accounts to vehicle commands.

Second-order effects

  • Other automakers operating comparable portals face renewed pressure to test authorization and API controls, following the earlier cross-industry findings in automakers’ remote-service APIs.
  • Owners and fleet customers may place greater weight on how quickly manufacturers disclose and remediate flaws in remote-control services, not just in-car hardware.

Third-order effects

  • If repeated portal-level flaws persist, connected-car security will increasingly be judged as an ongoing service-security obligation rather than a one-time vehicle feature.
  • The pattern strengthens the case for clearer accountability around the distribution layer that delivers remote vehicle commands, including disclosure and remediation practices.

The trend: Connected vehicles are shifting automotive cyber risk toward the web portals and APIs that mediate remote access, making service-layer security a core product responsibility.

Discussion

  • @hypervisible @hypervisible on bluesky
    “...researchers warn that the Subaru web vulnerabilities are just the latest in a long series of similar web-based flaws they and other security researchers working with them have found that have affected well over a dozen carmakers, including Acura, Genesis, Honda, Hyundai, Infi…
  • @joymwilliams @joymwilliams on bluesky
    Why would we want Elon Musk to know our every move?
  • @agreenberg Andy Greenberg on bluesky
    Security flaws in a Subaru web portal let hackers unlock, start ignition or access a year of detailed location history for millions of cars.  —  The flaws are now patched.  But they revealed powerful tracking abilities that Subaru employees can still access. www.wired.com/story/s…
  • @samwcyo Sam Curry on x
    New blog post with @infosec_au: We found a vulnerability in Subaru where an attacker, with just a license plate, could retrieve the full location history, unlock, and start vehicles remotely. The issue was reported and patched. Full post here: https://samcurry.net/...
  • @kashhill @kashhill on x
    Everything he describes having access to is what Subaru employees can see for drivers whose cars have Starlink. Connected cars are creating all kinds of data exhaust.