Skip to main content

Hackers remotely control jeep

Two US security experts have demonstrated security flaws in a Jeep Cherokee by taking wireless control of its systems from ten miles away. Writing on technology website Wired, Andy Greenberg, who was driving the jeep at the time, tells how Charlie Miller and Chris Valasek first toyed with the vehicle’s air conditioning, entertainment system and windscreen wipers, before cutting the transmission and causing the jeep to slowly come to a halt. Greenberg says, “The most disturbing manoeuvre came when they
July 22, 2015 Read time: 2 mins
Two US security experts have demonstrated security flaws in a Jeep Cherokee by taking wireless control of its systems from ten miles away.

Writing on technology website Wired, Andy Greenberg, who was driving the jeep at the time, tells how Charlie Miller and Chris Valasek first toyed with the vehicle’s air conditioning, entertainment system and windscreen wipers, before cutting the transmission and causing the jeep to slowly come to a halt.

Greenberg says, “The most disturbing manoeuvre came when they cut the jeep’s brakes, leaving me frantically pumping the pedal as the 2-ton SUV slid uncontrollably into a ditch.”

The researchers say they’re working on perfecting their steering control—for now they can only hijack the wheel when the jeep is in reverse. Their hack enables surveillance too: They can track a targeted jeep’s GPS coordinates, measure its speed, and even drop pins on a map to trace its route.

According to Greenberg, all of this is possible only because 1958 Chrysler, like many carmakers, is doing its best to turn the modern automobile into a smartphone. Uconnect, an internet-connected computer feature in hundreds of thousands of Fiat Chrysler cars, SUVs, and trucks, controls the vehicle’s entertainment and navigation, enables phone calls, and even offers a wi-fi hot spot. And thanks to one vulnerable element, which Miller and Valasek won’t currently identify, Uconnect’s cellular connection also lets anyone who knows the car’s IP address gain access from anywhere in the country.

“From an attacker’s perspective, it’s a super nice vulnerability,” Miller says.

Miller and Valasek say the attack on the entertainment system seems to work on any Chrysler vehicle with Uconnect from late 2013, all of 2014, and early 2015. They’ve only tested their full set of physical hacks, including ones targeting transmission and braking systems, on a Jeep Cherokee, though they believe that most of their attacks could be tweaked to work on any Chrysler vehicle with the vulnerable Uconnect head unit.

After being contacted by Miller and Valasek nine months ago, Fiat Chrysler developed a patch which must be manually implemented via a USB stick or by a dealership mechanic.

For more information on companies in this article

Related Content

  • Chrysler and Sprint developing a new wireless in-vehicle connectivity experience
    August 7, 2012
    Chrysler Group and Sprint have developed a new wireless in-vehicle connectivity experience for the Ram 1500 pickup and SRT Viper. The companies are evolving Uconnect to include a variety of new, easy-to-use connected features and services that are designed to help keep drivers focused on the primary driving task. Chrysler Group has enlisted the network, systems integration and consumer market expertise of Sprint in a strategic partnership designed to seamlessly integrate wireless technology into Chrysler Gr
  • Ford invests in next-generation driver assist technology
    November 4, 2016
    In addition to the driver assistance systems already in use on its card, new technology being developed by Ford includes cross-traffic alert with braking technology to help reduce parking stress by detecting people and objects about to pass behind the vehicle, providing a warning to the driver and then automatically braking if the driver does not respond. Rear wide-view camera, on the in-car display, will offer an alternative wide-angle view of the rear of the vehicle. Enhanced active park assist will paral
  • Drover AI’s Alex Nesic: ‘We’re still in the basement level of micromobility’
    April 12, 2022
    The micromobility revolution has reshaped the way we get around cities, but it has created some problems too. Drover AI’s PathPilot is here to help cities – and pedestrians – Alex Nesic tells Adam Hill
  • Need for secure approach to connected vehicle technology
    January 7, 2013
    Accidental or malicious issue of false messages to connected vehicles could result in dire consequences, so secure systems of authentication and certification are likely to be necessary, write Paul Avery and Sandra Dykes. Connectivity among vehicles in urban traffic systems will provide opportunity for beneficial impacts such as congestion reduction and greater safety. However, it also creates security risks with the potential for targeted disruption. Security algorithms, protocols and procedures must take