Honda Civics and Installing Software With Android Test Keys
News Source : Hackaday
News Summary
- A hacker has reverse-engineered the 2012-era Android-based infotainment system in a 2021 Honda Civic.
- In this exploit that [Eric] calls the EvilValet attack, it means that anyone with physical access to the USB port inside the car can theoretically run arbitrary code signed with these test keys.
- So far this rather foolish security issue has only been confirmed on the 2021 Civic, but considering how third-party systems tend to get reused and recycled across generations and car variants, it’s quite possible that more cars have this vulnerability.
Never miss a story from us, subscribe to our newsletter