BYD to issue security update for Shark 6 after hacking concerns | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


BYD is preparing a security update for its Shark 6 after researchers exposed potential cybersecurity weaknesses in the plug-in hybrid pick-up.

BYD is rolling out a security fix for its Shark 6 following a cybersecurity investigation

The Chinese car manufacturer will roll out an over-the-air update designed to prevent unauthorised software being installed through the vehicle’s Android-based infotainment system.

The move follows an investigation by Australian broadcaster ABC’s Four Corners programme, which enlisted cybersecurity specialists from Fortify Labs to examine the Shark 6.

Researcher Dan Hreszczuk was able to access a vehicle and demonstrate remote control of several functions, including its headlights, windscreen wipers and infotainment system.

The researchers were also able to track the vehicle’s location and access its cabin microphone.

However, the investigation did not demonstrate that an unknown hacker could remotely compromise a Shark 6 without first gaining physical access to the vehicle.

BYD subsequently launched its own investigation and said researchers had exploited a software defect to activate the Android Debug Bridge (ADB), a developer tool normally disabled on the vehicle.

The manufacturer said the flaw allowed an untrusted third-party application to be installed after physical access had been gained and permissions approved through the infotainment screen.

BYD plans to remove the unintended route used to activate ADB through a future software update, which will be released after validation testing.

The company also said the ability demonstrated by researchers to operate the headlights and wipers required direct physical access to the vehicle’s internal Controller Area Network (CAN) wiring.

More safety-critical systems were not compromised during the Four Corners test, with researchers reporting that they could not gain control of functions including the brakes.

Fortify Labs said the purpose of its work had been to simulate the level of remote access a vehicle manufacturer could potentially have to a connected car and explore how such access might be misused.

The episode highlights growing concerns surrounding cybersecurity as modern cars become increasingly reliant on internet connectivity, software and over-the-air updates.

BYD has not announced when the Shark 6 security update will be released.






Click Here For The Original Source.

——————————————————–

..........

.

.