• Home
    • What is
    • Computer security
      • Windows security
      • Mac security
      • Linux security
    • Mobile security
      • Android security
      • iOS Security
    • Data security
    • SCCM
    • Reviews
      • Case studies
    • Advertise
    • Contact
      • Privacy Policy
  • Subscribe now

    Loading
  • Home
  • What is
  • Computer security
    • Windows security
    • Mac security
    • Linux security
  • Mobile security
    • Android security
    • iOS Security
  • Data security
  • SCCM
  • Reviews
    • Case studies
  • Advertise
  • Contact
    • Privacy Policy
Home » Breaking Computer security Cyber Security data security Latest Cybersecurity News

SiriusXM vulnerability allows hackers to remotely control your cars

William Marshal Posted On December 5, 2022
0



SiriusXM Vulnerability

A security vulnerability discovered in several automobiles including Infinity, Nissan, Honda and Acura allow threat actors to execute remote attacks using connected vehicle service provided by SiriusXM.

The vulnerability will allow hackers to remotely unlock, start, honk and locate any car without any authority over it using the vehicle identification numbers (VIN), as per Sam Curry’s tweet.  

SiriusXM’s connected vehicles (CV) services are the ones that is being used by several vehicles in North America, including Hyundai, Infiniti, BMW, Acura, Land Rover, Jaguar, Nissan, Subaru and Toyota.

The system is designed to enable a wide range of security, safety, convenience services including automatic crash notification, roadside assistance, remote engine start, remote door unlock, stolen car recovery assistance, navigation and integration with IoT devices.

The SiriusXM Vulnerability and how it affects the cars

The SiriusXM vulnerability relates to an authorization flaw in their telematics program that made will allow the victim’s personal data to be retrieved and then execute commands on the vehicles by transmitting a specially crafted HTTP request containing the VIN number to a SiriusXM endpoint.

SiriusXM Vulnerability

Curry, the security researchers also mentioned that a different vulnerability is affecting Hyundai and Genesis vehicles that can abuse the car by remotely controlling their locks, engines, headlights, and trunks of the cars made using an email address.

By reverse engineering the MyGenesis and MyHyundai apps, inspecting API traffic, Curry found a route to manipulate the email validation process and take control of a car remotely.

He also said “By adding a CRLF character at the end of an already existing victim email address during registration, we could create an account which bypassed the JWT and email parameter comparison check”.

SiriusXM and Hyundai have since rolled out patches to address the SiriusXM vulnerability.

Subscribe to our newsletter for daily alerts on cyber events, you can also follow us on Facebook, Linkedin, and Twitter.

You can reach out to us via Twitter/ Facebook or mail us at admin@thecybersecuritytimes.com for advertising requests.

Share the article with your friends


CyberattackCybersecuritydata securityhacking


Author

William Marshal

William has been one of the key contributors to 'The Cybersecurity Times' with 9.5 years of experience in the cybersecurity journalism. Apart from writing, he also like hiking, skating and coding.

You may also like
Top 9 Best Log Management Tools for 2025
September 20, 2025
Top 4 Remote Support Tools for 2025- Best Remote Support Solution
September 18, 2025
Top 5 Best Unified Endpoint Management (UEM) Software for 2025
September 12, 2025
Leave A Reply

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

  • Subscribe to our newsletter

    Loading
  • Windows security

    • Top 9 Best Log Management Tools for 2025
      September 20, 2025
    • Top 4 Remote Support Tools for 2025- Best Remote Support...
      September 18, 2025
    • Top 5 Best Unified Endpoint Management (UEM) Software...
      September 12, 2025
    • Top 5 Threat Intelligence Tools For 2025
      July 25, 2025
    • Top 5 Best Microsoft Intune Alternatives to Consider...
      July 23, 2025


  • About us

    Our vision is to deliver the trending and happening cyber events to the enthusiasts.

    We believe in delivering educational and quality content for hassle-free understanding of the subject.

  • Subscribe to our newsletter

    Loading
  • Follow us

  • Advertise with us

    You can reach us via Facebook, Linkedin, or Twitter for advertising purposes.


© The Cybersecurity Times 2022. All rights reserved.
Press enter/return to begin your search