Focus on the BIG picture.
Thursday, Aug 14, 2025

Security flaws in a carmaker’s web portal let one hacker remotely unlock cars from anywhere

A security researcher discovered vulnerabilities in a carmaker’s online dealership portal, allowing potential remote access to vehicles and sensitive customer data.
A security researcher has uncovered significant flaws in a carmaker’s online dealership portal that exposed the private information of customers and could have enabled hackers to remotely access vehicles.

Eaton Zveare, a security researcher at Harness, discovered that the vulnerabilities allowed the creation of an admin account with full access to the carmaker’s centralized web portal.

This access could have allowed a hacker to view personal and financial data, track vehicles, and even pair cars with mobile accounts to control vehicle functions remotely.

The flaws were traced to an issue with the portal’s login system, where buggy code in the user’s browser allowed bypassing login security checks.

Once inside, the hacker could access data from over 1,000 dealerships across the United States.

Zveare found a national consumer lookup tool that allowed users to search vehicle and driver data by entering just a customer’s name or car’s unique identification number.

He also demonstrated how the vulnerability could have enabled unauthorized access to car functions such as unlocking vehicles.

Additionally, Zveare identified that the portal allowed users to impersonate others, bypassing the need for login credentials, and access dealer systems linked via single sign-on.

He found personally identifiable information, financial details, and real-time location tracking of rental or courtesy cars.

Zveare reported the issue to the carmaker, who fixed the vulnerabilities within a week.

The flaws highlight the risks of poor authentication in securing sensitive data and vehicle control systems.
Newsletter

Related Articles

0:00
0:00
Close
Spain requests EU assistance to tackle large wildfires
Sixty-Year-Old Claims: “My Biological Age Is Twenty-One.” Want the Same? Remember the Name Spermidine
Saudi Arabia accelerates renewables to curb domestic oil use
U.S. Investigation Reports No Russian Interference in Romanian Election First Round
The Billion-Dollar Inheritance and the Death on the Railway Tracks: The Scandal Shaking Europe
Oasis Reunion Tour Linked to Temporary Rise in UK Inflation
World’s Cleanest Countries 2025 Ranked by Air, Water, Waste, and Hygiene Standards
Trump Extends US-China Tariff Truce for 90 Days
Musk Alleges Apple Favors OpenAI in App Store Rankings
Denmark Revives EU ‘Chat Control’ Proposal for Encrypted Message Scanning
Trump Criticizes Goldman Sachs Over Tariff Cost Forecasts
Perplexity makes unsolicited $34.5 billion all-cash offer for Google’s Chrome browser
Kodak warns of liquidity crisis as debt obligations loom
Cristiano Ronaldo and Georgina Rodríguez announce engagement
Taylor Swift announces 12th studio album on Travis Kelce’s podcast after high-profile year together
South Korean court orders arrest of former First Lady Kim Keon Hee on bribery and corruption allegations
Asia-Pacific dominates world’s busiest flight routes, with South Korea’s Jeju–Seoul corridor leading global rankings
Private Welsh island with 19th-century fort listed for sale at over £3 million
Cathay Pacific offers consecutive rounds of voluntary unpaid leave for cabin crew amid investment and profit updates
Sam Altman challenges Elon Musk with plans for Neuralink rival
DC paid protester requests surge 400% amid Trump’s federal takeover of city police: crowd company CEO says vast majority of political event attendees in Washington are paid in some way
Zelenskyy Excluded from Trump-Putin Alaska Talks as White House Cites Bilateral Format
Trump and Putin Meeting: Focus on Listening and Communication
Trump will reassess DC crime crackdown after 30 days
Where Are the New Billionaires Coming From? Ask ChatGPT
Instagram Released a New Feature – and Sent Users Into a Panic
China Accuses: Nvidia Chips Are U.S. Espionage Tools
Mercedes’ CEO Is Killing Germany’s Auto Legacy
Nvidia and AMD Strike Revenue-Sharing Deal to Sell AI Chips in China
Markets Slip as Semiconductor Sector Faces New Revenue-Sharing Demands
Trump Extends Tariff Truce With China by 90 Days
Concerns Over Inflation Data Integrity After BLS Chief Fired
Trump Declares Crime Emergency in Washington, D.C.
Trump Federalizes D.C. Police and Deploys Troops
Trial Opens Over Trump’s Use of Military in Los Angeles Protests
Markets Slip as Government Targets AI-Chip Exports
Trump Proposes Land Concessions to End Ukraine War
Deadly Explosion at U.S. Steel Plant in Pennsylvania
New Road Safety Measures Proposed in the UK: Focus on Eye Tests and Stricter Drink-Driving Limits
Viktor Orbán Criticizes EU's Financial Support for Ukraine Amid Economic Concerns
Trump Promise that Tariffs Will Make America Richer Than Ever. If You Pay Less Taxes, It's True!
South Korea's Military Shrinks by 20% Amid Declining Birthrate
US Postal Service Targets Unregulated Vape Distributors in Crackdown
Duluth International Airport Running on Tech Older Than Your Grandmother's Vinyl Player
RFK Jr. Announces HHS Investigation into Big Pharma Incentives to Doctors
Australia to Recognize the State of Palestine at UN Assembly
The Collapse of the Programmer Dream: AI Experts Now the Real High-Earners
Security flaws in a carmaker’s web portal let one hacker remotely unlock cars from anywhere
Denmark Pushes for Child Sexual Abuse Scanning Bill in EU, Could Be Adopted by October 2025
Armenia and Azerbaijan sign U.S.-brokered accord at White House outlining transit link via southern Armenia
×