Mercedes-Benz App Glitch Exposes Customer Data to Other Drivers

A security lapse in the Mercedes-Benz connected car app allows users to view sensitive account and vehicle information belonging to complete strangers. The company takes the app offline for maintenance shortly after customers report the bizarre data mix-up.

A glitch in the Mercedes-Benz connected car app exposes private customer data to other users, allowing them to see strangers' names, phone numbers, and recent vehicle activity. Multiple Seattle-based car owners report that when they open the app, it pulls in account details and vehicle information from entirely different people instead of their own profiles. This apparent security lapse occurs late on a Friday before the company takes the app offline, labeling the sudden downtime as routine site maintenance.

While the malfunction gives users access to another person's profile, it fortunately does not grant them full control over the exposed vehicles. The app displays the recent travel history and locations of the mismatched cars, but it does not allow users to track the real-time location of the vehicles. Additionally, the remote lock, unlock, and engine start features do not work during this glitch, which significantly limits the potential physical security risks associated with the data mix-up.

Mercedes-Benz customer service tells affected users to simply delete the app from their phones until the problem is fixed. A spokesperson for Daimler, the parent company of Mercedes-Benz, later confirms that a short interval of incorrect customer data display occurs due to a caching issue. Although the exact cause and the full scope of the exposure remain unclear, the incident highlights the ongoing privacy risks that come with modern internet-connected vehicles.

Read More at the original source →