Millions of vehicles contain hackable aftermarket alarm systems that dealerships installed without owner knowledge or consent, according to new security research. The vulnerabilities allow remote attackers to unlock doors, track vehicle locations in real time, and completely disable affected cars. The security flaws affect alarm systems that dealerships commonly add to vehicles as part of sales packages, often leaving them installed and active even when buyers decline the add-on purchase.
Dealerships have routinely installed these alarm systems across their inventory as a standard practice, sometimes removing them if customers refuse the additional charge but frequently leaving the hardware in place. Many vehicle owners remain unaware that their cars contain these connected devices, which continue to communicate with remote servers and respond to commands. The practice has created a hidden attack surface affecting an estimated millions of vehicles currently on the road.
The technical vulnerabilities center on weak authentication mechanisms and insecure communication protocols in the alarm systems. Researchers found that attackers could intercept and manipulate commands sent between the alarm hardware and backend servers. The systems lack proper encryption and verification, allowing unauthorized users to send commands that the vehicle hardware accepts as legitimate. Remote exploitation requires no physical access to the target vehicle, making the attacks practical for criminals seeking to steal cars or track specific individuals.
The security flaws pose immediate risks to vehicle owners, particularly those unaware their cars contain the vulnerable systems. Car thieves could exploit the vulnerabilities to unlock and disable vehicles remotely, while stalkers or domestic abusers could use the tracking capabilities to monitor victims. The widespread deployment across dealership inventories means the problem affects multiple vehicle makes and models, not just a single manufacturer or alarm brand.
Vehicle owners should contact their dealerships to determine if their cars contain these alarm systems and request complete removal of the hardware if present. Simply disconnecting or deactivating the systems may not eliminate the risk if the hardware remains capable of receiving commands. Owners should also review their purchase documents and financing agreements to identify any alarm-related charges, as some dealerships may have billed for systems that buyers explicitly declined. Until manufacturers and dealerships address these vulnerabilities, affected vehicles remain at significant risk of unauthorized access and tracking.
Source: https://www.wired.com/story/a-device-hidden-in-cars-across-the-us-leaves-them-vulnerable-to-hacking-and-paralysis-patch-it-now/


