Skip to main content

Hackers remotely control jeep

Two US security experts have demonstrated security flaws in a Jeep Cherokee by taking wireless control of its systems from ten miles away. Writing on technology website Wired, Andy Greenberg, who was driving the jeep at the time, tells how Charlie Miller and Chris Valasek first toyed with the vehicle’s air conditioning, entertainment system and windscreen wipers, before cutting the transmission and causing the jeep to slowly come to a halt. Greenberg says, “The most disturbing manoeuvre came when they
July 22, 2015 Read time: 2 mins
Two US security experts have demonstrated security flaws in a Jeep Cherokee by taking wireless control of its systems from ten miles away.

Writing on technology website Wired, Andy Greenberg, who was driving the jeep at the time, tells how Charlie Miller and Chris Valasek first toyed with the vehicle’s air conditioning, entertainment system and windscreen wipers, before cutting the transmission and causing the jeep to slowly come to a halt.

Greenberg says, “The most disturbing manoeuvre came when they cut the jeep’s brakes, leaving me frantically pumping the pedal as the 2-ton SUV slid uncontrollably into a ditch.”

The researchers say they’re working on perfecting their steering control—for now they can only hijack the wheel when the jeep is in reverse. Their hack enables surveillance too: They can track a targeted jeep’s GPS coordinates, measure its speed, and even drop pins on a map to trace its route.

According to Greenberg, all of this is possible only because 1958 Chrysler, like many carmakers, is doing its best to turn the modern automobile into a smartphone. Uconnect, an internet-connected computer feature in hundreds of thousands of Fiat Chrysler cars, SUVs, and trucks, controls the vehicle’s entertainment and navigation, enables phone calls, and even offers a wi-fi hot spot. And thanks to one vulnerable element, which Miller and Valasek won’t currently identify, Uconnect’s cellular connection also lets anyone who knows the car’s IP address gain access from anywhere in the country.

“From an attacker’s perspective, it’s a super nice vulnerability,” Miller says.

Miller and Valasek say the attack on the entertainment system seems to work on any Chrysler vehicle with Uconnect from late 2013, all of 2014, and early 2015. They’ve only tested their full set of physical hacks, including ones targeting transmission and braking systems, on a Jeep Cherokee, though they believe that most of their attacks could be tweaked to work on any Chrysler vehicle with the vulnerable Uconnect head unit.

After being contacted by Miller and Valasek nine months ago, Fiat Chrysler developed a patch which must be manually implemented via a USB stick or by a dealership mechanic.

Related Content

  • June 18, 2015
    Land Rover demonstrates remote-control Range Rover Sport
    Jaguar Land Rover, part of the UK Autodrive consortium, has demonstrated a remote control Range Rover Sport research vehicle, showing how a driver could drive the vehicle from outside the car via their smartphone. The smartphone app includes control of steering, accelerator and brakes as well as changing from high and low range. This would allow the driver to walk alongside the car, at a maximum speed of 4mph, to manoeuvre their car out of challenging situations safely, or even to negotiate difficult off
  • January 20, 2017
    Automotive software developers call on hackers to find its flaws
    A consortium of US researchers has announced the development of a universal, free, and open-source framework to protect wireless software updates in vehicles. The team issued a challenge to security experts everywhere to try to find vulnerabilities before it is adopted by the automotive industry. The new solution, called Uptane, evolves the widely used TUF (The Update Framework), developed by NYU Tandon School of Engineering Assistant Professor of Computer Science and Engineering Justin Cappos to secure
  • March 4, 2015
    Major car makers opt for TomTom
    TomTom has announced new deals with motor manufacturers Kia Motors Europe, Fiat/Chrysler in Latin America and Hyundai in Europe. Starting in summer 2015, the company will integrate its connected services, including TomTom Traffic, speed cameras, local search and weather, in new Kia cars, beginning with the Kia cee’d and Kia Optima, and in Hyundai cars starting with the launch of the All-New Tucson SUV in the second half of 2015. Kia and Hyundai customers will benefit from the delivery of TomTom’s connected
  • August 5, 2016
    Michigan researchers show how easy it is to hack trucks
    Cybersecurity researchers have already shown how easy it is to hack a Jeep Cherokee and take control of its brakes and steering, resulting in a recall for the vulnerability to be corrected. At the Usenix Workshop on Offensive Technologies conference next week, a group of University of Michigan researchers plan to demonstrate how trucks, which have also begun adding similar electronic control system, can be vulnerable to hacking. They plan to show how the openness of the SAE J1939 standard used across