Thieves Can Use Two Small Bluetooth Relay Devices and a Laptop To Unlock and Start Your Car in Seconds

Thieves Can Use Two Small Bluetooth Relay Devices and a Laptop To Unlock and Start Your Car in Seconds 图片 1

No smashed window. No hotwire. A thief sits in a parking lot with a laptop and two relay devices smaller than a deck of cards. Your car unlocks itself, engine ready. Two separate lines of security research — one targeting the Bluetooth stack inside infotainment systems, the other exploiting the phone-as-key feature built into millions of modern vehicles — have converged on the same conclusion. Bluetooth is the softest entry point on vehicles from Mercedes-Benz, Volkswagen, Skoda, Tesla, and others.

Two Attacks, One Weak Link

Researchers found flaws in both the software running your dashboard and the signal connecting your phone to your car.

PCA Cyber Security discovered four critical vulnerabilities — dubbed PerfektBlue, tracked as CVE-2024-45431 through CVE-2024-45434 — in BlueSDK, a Bluetooth stack embedded in infotainment units across multiple automakers. One user click while in pairing range can hand an attacker remote code execution, according to PCA Cyber Security. From there: location tracking, audio recording, stolen contacts, and in vehicles with poor network segmentation, potential access to powertrain controls. OpenSynergy released patches in September 2024, but those fixes still require automakers to actually push them to your dashboard.NCC Group’s BLE relay attack works differently. Place one relay device near the owner’s phone — roughly 30 feet away — and another near the car at about 10 feet. The Tesla Model Y the researchers tested unlocked and started without the physical key anywhere near it. Standard Bluetooth tops out around 10 meters, but amplified setups can reach 50–100 meters, roughly the span of a grocery store parking lot. Engine disruption via Bluetooth remains theoretical in most architectures — no documented real-world remote engine shutdowns exist yet — and a separate USENIX study found 128 vulnerabilities across 22 cars from 14 brands, confirming that outdated Bluetooth stacks ship constantly.

“This proves that any product relyi…

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论