Major Car Alarm Flaws Allowed Remote Vehicle Hijacking

Security researchers discover severe API vulnerabilities in Pandora and Viper car alarms that allow remote tracking, engine shutdown, and eavesdropping on millions of vehicles. Both companies quickly fix the issues after a brief disclosure period.

Researchers at Pen Test Partners uncover severe security vulnerabilities in popular car alarm systems made by Pandora and Viper. The flaws stem from a weak server-side API that fails to verify authorized requests, allowing anyone to easily reset user account passwords and gain full control of the alarm system. This breach exposes approximately three million vehicles globally to remote attacks.

The hackers demonstrate just how dangerous these flaws are by successfully geolocating a target vehicle, tracking its movement in real time, and remotely killing the engine to force the car to stop. The attackers also unlock the vehicle doors and activate the built-in microphone in Pandora systems to eavesdrop on conversations inside the car. The researchers note that identifying specific car models makes it trivially easy to target high-end vehicles.

Both Pandora and Viper respond rapidly to fix the vulnerabilities after the researchers issue a strict seven-day disclosure deadline. Viper blames a recent system update by a service provider for the bug and claims that no customer data is exposed, though the company provides no evidence to support this assertion. Meanwhile, Pandora works to patch its systems as researchers highlight this as their most significant project to date.

Read More at the original source →