Skip to main content

Hackers remotely control jeep

Two US security experts have demonstrated security flaws in a Jeep Cherokee by taking wireless control of its systems from ten miles away. Writing on technology website Wired, Andy Greenberg, who was driving the jeep at the time, tells how Charlie Miller and Chris Valasek first toyed with the vehicle’s air conditioning, entertainment system and windscreen wipers, before cutting the transmission and causing the jeep to slowly come to a halt. Greenberg says, “The most disturbing manoeuvre came when they
July 22, 2015 Read time: 2 mins
Two US security experts have demonstrated security flaws in a Jeep Cherokee by taking wireless control of its systems from ten miles away.

Writing on technology website Wired, Andy Greenberg, who was driving the jeep at the time, tells how Charlie Miller and Chris Valasek first toyed with the vehicle’s air conditioning, entertainment system and windscreen wipers, before cutting the transmission and causing the jeep to slowly come to a halt.

Greenberg says, “The most disturbing manoeuvre came when they cut the jeep’s brakes, leaving me frantically pumping the pedal as the 2-ton SUV slid uncontrollably into a ditch.”

The researchers say they’re working on perfecting their steering control—for now they can only hijack the wheel when the jeep is in reverse. Their hack enables surveillance too: They can track a targeted jeep’s GPS coordinates, measure its speed, and even drop pins on a map to trace its route.

According to Greenberg, all of this is possible only because 1958 Chrysler, like many carmakers, is doing its best to turn the modern automobile into a smartphone. Uconnect, an internet-connected computer feature in hundreds of thousands of Fiat Chrysler cars, SUVs, and trucks, controls the vehicle’s entertainment and navigation, enables phone calls, and even offers a wi-fi hot spot. And thanks to one vulnerable element, which Miller and Valasek won’t currently identify, Uconnect’s cellular connection also lets anyone who knows the car’s IP address gain access from anywhere in the country.

“From an attacker’s perspective, it’s a super nice vulnerability,” Miller says.

Miller and Valasek say the attack on the entertainment system seems to work on any Chrysler vehicle with Uconnect from late 2013, all of 2014, and early 2015. They’ve only tested their full set of physical hacks, including ones targeting transmission and braking systems, on a Jeep Cherokee, though they believe that most of their attacks could be tweaked to work on any Chrysler vehicle with the vulnerable Uconnect head unit.

After being contacted by Miller and Valasek nine months ago, Fiat Chrysler developed a patch which must be manually implemented via a USB stick or by a dealership mechanic.

Related Content

  • May 18, 2015
    Green light for Google self-driving vehicle prototypes
    Google has announced the next step in its autonomous vehicle program and is about to begin testing its new prototype self-driving vehicles on public roads. This summer, the company will move its cars from the test track to the roads with safety drivers aboard. The company has been rigorously testing the cars at its test facilities for several years. The new prototypes are based on the company’s existing fleet of self-driving Lexus RX450h SUVs, which has logged nearly a million autonomous miles and recen
  • September 8, 2015
    Hackers can fool self-driving car sensors into evasive action
    The laser ranging (LIDAR) systems that most self-driving cars rely on to sense obstacles can be hacked by a setup costing just US$60, a security researcher has told IEEE spectrum. According to Jonathan Petit, principal scientist at software security company Security Innovation, he can take echoes of a fake car, pedestrian or wall and put them in any location. Using such a system, which he designed using a low-power laser and pulse generator, attackers could trick a self-driving car into thinking somethin
  • November 7, 2014
    Electric car value chain overturned
    The market for hybrid and pure electric cars homologated as such is set to be US$188 billion in 2025 according to IDTechEx analysis. However, according to Dr Peter Harrop, chairman of IDTechEx, the world has changed for cars overall and now big is not always beautiful for mainstream car manufacture. EVs will reflect this. Although Sergio Marchionne, boss of Fiat Chrysler, famously said six million units a year is needed for a car maker to be profitable, his head of research Pietro Perlo left to successf
  • May 4, 2017
    Nissan uses 180 year-old invention to tackle smartphone distraction behind the wheel
    Nissan GB has adopted a technology that’s almost 200 years old to create a concept solution for reducing the growing problem of smartphone distraction at the wheel. The Nissan Signal Shield is a prototype compartment within the arm rest of a Nissan Juke that is lined with a Faraday cage, an invention dating back to the 1830s, consisting of an enclosure made of a conductive material, such as wire mesh, which blocks electromagnetic fields. Once a mobile device is placed in the compartment and the lid closed,