Researchers detail Subaru's now-fixed web vulnerabilities that would've let them unlock and start millions of Subarus via Starlink in the US, Canada, and Japan
Now-fixed web bugs allowed hackers to remotely unlock and start millions of Subarus. More disturbingly, they could also access …
Context & Ripple Effects
This is another case of connected-vehicle access being exposed through a web service rather than a physical break-in. A 2023 study had already identified API weaknesses across nearly 20 automakers that could expose remote lock, start, and tracking functions.
The Subaru disclosure also follows a recent Kia portal flaw with similar remote-control implications. Together, the cases make the security of manufacturer web portals and their authorization flows central to vehicle safety and customer trust.
First-order effects
- Subaru’s fixes remove the reported path for attackers to remotely unlock and start affected vehicles in the US, Canada, and Japan.
- The disclosure puts Subaru’s remote-access systems under sharper scrutiny, particularly the web controls that connect customer accounts to vehicle commands.
Second-order effects
- Other automakers operating comparable portals face renewed pressure to test authorization and API controls, following the earlier cross-industry findings in automakers’ remote-service APIs.
- Owners and fleet customers may place greater weight on how quickly manufacturers disclose and remediate flaws in remote-control services, not just in-car hardware.
Third-order effects
- If repeated portal-level flaws persist, connected-car security will increasingly be judged as an ongoing service-security obligation rather than a one-time vehicle feature.
- The pattern strengthens the case for clearer accountability around the distribution layer that delivers remote vehicle commands, including disclosure and remediation practices.
The trend: Connected vehicles are shifting automotive cyber risk toward the web portals and APIs that mediate remote access, making service-layer security a core product responsibility.