The vulnerabilities discovered in Skoda's MIB3 infotainment unit could allow attackers to remotely trigger controls and track the cars' location, posing significant security risks.
Danila Parnishchev emphasized the severity of the vulnerabilities, stating that an attacker could execute unrestricted code every time the infotainment unit starts, leading to potential live tracking.
Parnishchev revealed that the infotainment unit's weaknesses enable hackers to exfiltrate users' contacts due to the database being stored in plaintext, heightening privacy concerns.
The research also highlighted that once an attacker connects through Bluetooth within a range of 10 meters, they can perform various malicious actions without authentication.
Collection
[
|
...
]