• News/
  • https://www.bleepingcomputer.com/news/security/subaru-starlink-flaw-let-hackers-hijack-cars-in-us-and-canada/

Subaru Starlink flaw let hackers hijack cars in US and Canada

BleepingComputer
·
Sergiu Gatlan
·
Published Jan 24, 2025
·
Updated

Security researchers have discovered an arbitrary account takeover flaw in Subaru's Starlink service that could let attackers track, control, and hijack vehicles in the United States, Canada, and Japan using just a license plate. Bug bounty hunter Sam Curry revealed on Thursday that the vulnerability was discovered on November 20, 2024, with the help of researcher Shubham Shah. They found that the security flaw gave potential attackers unrestricted targeted access to all U.S., Canadian, and Japanese customer accounts and vehicles. The only requirements were previous knowledge of the victim's last name and ZIP code, email address, phone number, or license plate. Among other things, successful exploitation could have allowed hackers targeting Subaru customers to: Curry also shared a video demonstrating how the Starlink vulnerability could be exploited to get more than a year's worth of location data for a Subaru car within just 10 seconds. As the researcher discovered, Subaru Starlink's admin portal contained an arbitrary account takeover flaw stemming from a "resetPassword.json" API endpoint designed to allow Subaru employees to reset their accounts using a valid email without a confirmation token. After taking over an employee's account, Curry also had to bypass a two-factor authentication (2FA) prompt to access the portal. However, this was also easily circumvented by removing the client-side overlay from the portal's user interface. "There were a ton of other endpoints. On...

Read full article

Affected Software

2 affected components
Subaru Starlink
Subaru Starlink
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203