Security researchers have discovered an arbitrary account takeover flaw in Subaru's Starlink service that could let attackers track, control, and hijack vehicles in the United States, Canada, and Japan using just a license plate. Bug bounty hunter Sam Curry revealed on Thursday that the vulnerability was discovered on November 20, 2024, with the help of researcher Shubham Shah. They found that the security flaw gave potential attackers unrestricted targeted access to all U.S., Canadian, and Japanese customer accounts and vehicles. The only requirements were previous knowledge of the victim's last name and ZIP code, email address, phone number, or license plate. Among other things, successful exploitation could have allowed hackers targeting Subaru customers to: Curry also shared a video demonstrating how the Starlink vulnerability could be exploited to get more than a year's worth of location data for a Subaru car within just 10 seconds. As the researcher discovered, Subaru Starlink's admin portal contained an arbitrary account takeover flaw stemming from a "resetPassword.json" API endpoint designed to allow Subaru employees to reset their accounts using a valid email without a confirmation token. After taking over an employee's account, Curry also had to bypass a two-factor authentication (2FA) prompt to access the portal. However, this was also easily circumvented by removing the client-side overlay from the portal's user interface. "There were a ton of other endpoints. On...
Subaru Starlink flaw let hackers hijack cars in US and Canada
BleepingComputer
·Sergiu Gatlan
·Published Jan 24, 2025
·Updated
Affected Software
2 affected components
Subaru Starlink
Subaru Starlink