Skip to main content

Hackers remotely control jeep

Two US security experts have demonstrated security flaws in a Jeep Cherokee by taking wireless control of its systems from ten miles away. Writing on technology website Wired, Andy Greenberg, who was driving the jeep at the time, tells how Charlie Miller and Chris Valasek first toyed with the vehicle’s air conditioning, entertainment system and windscreen wipers, before cutting the transmission and causing the jeep to slowly come to a halt. Greenberg says, “The most disturbing manoeuvre came when they
July 22, 2015 Read time: 2 mins
Two US security experts have demonstrated security flaws in a Jeep Cherokee by taking wireless control of its systems from ten miles away.

Writing on technology website Wired, Andy Greenberg, who was driving the jeep at the time, tells how Charlie Miller and Chris Valasek first toyed with the vehicle’s air conditioning, entertainment system and windscreen wipers, before cutting the transmission and causing the jeep to slowly come to a halt.

Greenberg says, “The most disturbing manoeuvre came when they cut the jeep’s brakes, leaving me frantically pumping the pedal as the 2-ton SUV slid uncontrollably into a ditch.”

The researchers say they’re working on perfecting their steering control—for now they can only hijack the wheel when the jeep is in reverse. Their hack enables surveillance too: They can track a targeted jeep’s GPS coordinates, measure its speed, and even drop pins on a map to trace its route.

According to Greenberg, all of this is possible only because 1958 Chrysler, like many carmakers, is doing its best to turn the modern automobile into a smartphone. Uconnect, an internet-connected computer feature in hundreds of thousands of Fiat Chrysler cars, SUVs, and trucks, controls the vehicle’s entertainment and navigation, enables phone calls, and even offers a wi-fi hot spot. And thanks to one vulnerable element, which Miller and Valasek won’t currently identify, Uconnect’s cellular connection also lets anyone who knows the car’s IP address gain access from anywhere in the country.

“From an attacker’s perspective, it’s a super nice vulnerability,” Miller says.

Miller and Valasek say the attack on the entertainment system seems to work on any Chrysler vehicle with Uconnect from late 2013, all of 2014, and early 2015. They’ve only tested their full set of physical hacks, including ones targeting transmission and braking systems, on a Jeep Cherokee, though they believe that most of their attacks could be tweaked to work on any Chrysler vehicle with the vulnerable Uconnect head unit.

After being contacted by Miller and Valasek nine months ago, Fiat Chrysler developed a patch which must be manually implemented via a USB stick or by a dealership mechanic.

For more information on companies in this article

Related Content

  • Debating the future of in-vehicle systems
    December 6, 2012
    Industry experts talk to Jason Barnes about the legislative situation of current and future in-vehicle systems. Articles about technology development can have a tendency to reference Moore’s Law with almost indecent regularity and haste but the fact remains that despite predictions of slow-down or plateauing, the pace remains unrelenting. That juxtaposes with a common tendency within the ITS industry: to concentrate on the technology and assume that much else – legislation, business cases and so on – will m
  • Buses services benefit from seamless Wi-Fi data transfer
    April 9, 2014
    Ted Bowser explains how the almost total Wi-Fi coverage at Ride-On’s new bus garage is providing big benefits for the operator and passengers alike. The ability to download and upload data to and from the various systems on board buses has become central to mass transit operators’ business model. So when Ride-On, the public transportation system in Maryland’s Montgomery County, was moving one of its three depots into a bigger and purpose-built facility, connectivity was a key consideration.
  • Ken Leonard talks to ITS International
    August 21, 2014
    Ken Leonard, director of the USDOT’s ITS Joint Program office made time in his schedule during the Helsinki Congress to speak to ITS International. It has been 18 months since Ken Leonard took over as the director of the Intelligent Transportation Systems Joint Program Office at the US Department of Transportation. With 30 years of technical experience behind him, to say he is enjoying the challenge would be to put it mildly: “It is incredibly exciting to be working in intelligent transportation systems, th
  • Nissan’s new Serena comes equipped with autonomous technology
    July 15, 2016
    Nissan Motor Company’s new Serena, due to go on sale in Japan in August, will come equipped with the company’s ProPILOT autonomous drive technology, designed for highway use in single-lane traffic. ProPILOT will assist with steering, accelerator and braking, controlled from a mono camera equipped with image processing software which recognises road and traffic situations, as well as lane markers. The system is activated and deactivated b y the driver using a switch on the steering wheel. Once activate