LIVE · cybersecurity feed
Live wire
vulnerability

The automotive software vulnerabilities hiding in your dashboard

Pop the hood on a new car and you won’t find much you can fix with a wrench. What you’ll find is software, and a lot of it. The screen in the dash probably runs Android or a flavor of Linux. The system watching the road for you might run QNX or VxWorks, the same kind of code that flies aircraft and runs factory floors. Carmakers spent the last decade making this switch, and it … More → The post Th

zeroday.news · 8d ago

The increasing reliance on software in modern vehicles has introduced a significant number of known vulnerabilities into automotive systems, according to research conducted by Télécom SudParis. As car manufacturers integrate general-purpose operating systems like Android and Linux into dashboards and control units, they also inherit the accumulated security flaws documented for these platforms.

Researchers developed a scanner called VERA to identify known vulnerabilities within the operating systems used in current vehicles. Their findings indicate a wide range in the number of documented flaws across different platforms. Automotive Grade Linux, for instance, showed 1,203 known vulnerabilities in the tested version, with Android not far behind. In contrast, the safety-focused Eclipse S-CORE platform registered only eight. This disparity is attributed to factors like the volume of software shipped with each platform and the level of scrutiny popular open-source projects receive from researchers.

Even systems with security certifications were not immune. QNX Neutrino, despite its respected certification, was found to have 56 known vulnerabilities in its tested build, while VxWorks 7, with an even higher certification tier, also contained dozens of flaws. While certification helps reduce the attack surface and enforces development discipline, it cannot prevent new bugs from emerging in the surrounding software components.

The researchers emphasized that a high number of documented vulnerabilities does not equate to an equivalent number of exploitable entry points into a vehicle. A logged vulnerability represents a potential weakness that may only be relevant under specific conditions, depending on whether the vulnerable code is active, accessible to an attacker, and if the system configuration aligns.

To illustrate this point, the team developed two proof-of-concept attacks. One targeted a bug in SQLite, a database engine often embedded in Android Automotive applications. The other focused on SOME/IP, a service discovery protocol. The SOME/IP attack was successful in knocking a service offline on Red Hat's AutoSD and Tesla's software, but it failed on Android Automotive, which the researchers attributed to the platform dynamically reconfiguring its port numbers. This demonstrated that the practical impact of a vulnerability can vary significantly across different implementations, even with the same reported severity score.

It is important to note that these tests were conducted in Docker containers in a lab environment, which accurately replicated the filesystem, installed packages, and configurations. However, this setup did not account for vendor-specific custom kernels, firmware quirks, or hardware-level protections that would be present in an actual vehicle. The numbers primarily reflect the vulnerabilities present in the software image itself.

The research also highlighted challenges with existing security scanning tools, which often produce numerous false positives when applied to automotive systems. VERA addresses this by filtering out flaws in command-line utilities and developer tools that would not be exposed in a locked-down car environment, providing a more relevant and actionable list of vulnerabilities for defenders. The study concludes that while automotive software now shares a common lineage and a history of vulnerabilities with the broader computing world, the critical task lies in identifying which of these known flaws pose a genuine risk to a specific vehicle.

vulnerabilitypatch
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Microsoft blames massive Microsoft 365 outage on maintenance bug

Microsoft says a bug in its automated network maintenance request system caused Thursday's massive outage by mistakenly removing IP routes from more devices than intended, disrupting Azure and Microsoft 365 services. [...]

breach

Hermes AI agent used to automate attack on Thai Finance Ministry

A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. [...]

security

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. [...]

security

BGP ORIGIN attribute manipulation and its impact on the Internet

By doing in-depth testing, we found nearly 70% of BGP paths experience ORIGIN attribute rewrites by transit providers seeking traffic advantages. We examine the global impact of this practice and argue for deprecating ORIGIN in route selection.

security

Andy Burnham signals continuity on UK cyber policy, reappoints minister despite scrapping ministry

The new British prime minister is retaining Liz Lloyd in a cyber policy role, making her one of the few Keir Starmer allies remaining in government.

security

'Wrench' attacks against crypto holders appear to be on the rise

There are more reports than ever before of strong-arm tactics like home invasions and kidnappings against cryptocurrency holders, researchers say.