Researchers Expose 4 Bluetooth Flaws Letting Thieves Unlock and Start Cars Remotely
Updated
Updated · Yahoo Autos · Jul 21
Researchers Expose 4 Bluetooth Flaws Letting Thieves Unlock and Start Cars Remotely
3 articles · Updated · Yahoo Autos · Jul 21
Summary
PCA Cyber Security and NCC Group showed two Bluetooth-based attack paths that can unlock and start modern cars remotely, including a tested Tesla Model Y, without a physical key nearby.
Four critical BlueSDK flaws — CVE-2024-45431 through CVE-2024-45434 — can give attackers remote code execution in infotainment systems after one user click in pairing range, opening paths to tracking, audio capture and, in poorly segmented vehicles, possible powertrain access.
A separate BLE relay attack needs one device near the owner's phone and another near the car; researchers said boosted setups can stretch Bluetooth reach to 50-100 meters across a parking lot.
OpenSynergy issued BlueSDK patches in September 2024, but protection depends on automakers pushing dashboard updates; Volkswagen said range, ignition state and user approval limit practical risk.
A USENIX study found 128 vulnerabilities across 22 cars from 14 brands, underscoring how default-on phone-as-key and telematics features have widened vehicles' attack surface.
A secret device from your car dealer could let thieves in. Do you know how to find and disable this hidden threat?
Security patches have existed for years. Why are automakers still selling cars with old vulnerabilities that put owners at risk?
Millions of Cars at Risk: The 2025 PerfektBlue Bluetooth Vulnerabilities and the Urgent Need for Automotive Cybersecurity
Overview
In 2025, PCA Cyber Security discovered the PerfektBlue vulnerabilities, which were assigned CVE-2024-45431 through CVE-2024-45434. These flaws target the widely used OpenSynergy BlueSDK Bluetooth stack found in modern vehicle infotainment systems, affecting millions of devices across the automotive industry. The vulnerabilities allow unauthorized access to a car’s infotainment system under specific conditions, but Volkswagen clarified that only Bluetooth connectivity is impacted and that vehicle safety or integrity is not compromised. This highlights the growing cybersecurity risks in connected cars, emphasizing the need for prompt software updates and user vigilance.