Skip to main content

Jeep hackers return to remotely hack Cherokee’s digital systems

Just a year after they caused Chrysler to recall 1.4 million Jeep Cherokee vehicles after showing how they could remotely hijack a jeep’s digital systems over the internet, Charlie Miller and Chris Valasek are back to show how it could get worse. In the 2015 attack, they first toyed with the vehicle’s air conditioning, entertainment system and windscreen wipers, before cutting the transmission and causing the jeep to slowly come to a halt. At the Black Hat USA 2016 conference this week the two automot
August 4, 2016 Read time: 2 mins
RSSJust a year after they caused 1958 Chrysler to recall 1.4 million Jeep Cherokee vehicles after showing how they could remotely hijack a jeep’s digital systems over the internet, Charlie Miller and Chris Valasek are back to show how it could get worse.

In the 2015 attack, they first toyed with the vehicle’s air conditioning, entertainment system and windscreen wipers, before cutting the transmission and causing the jeep to slowly come to a halt.

At the Black Hat USA 2016 conference this week the two automotive cybersecurity researchers will outline new methods of cyber attack against the same Jeep Cherokee they hacked last year.

According to Miller and Valasek, hackers usually inject CAN messages on to the vehicle's network. However, there are often many limitations on what actions the vehicle can be forced to perform when injecting CAN messages. While an attacker may be able to easily change the speedometer while the car is driving, he may not be able to disable the brakes or turn the steering wheel unless the car he is driving meets certain prerequisites, such as travelling below a certain speed.

In their presentation, they plan to discuss how physical, safety critical systems react to injected CAN messages and how these systems are often resilient to this type of manipulation.

They will also outline new methods of CAN message injection which can bypass many of these restrictions and demonstrate the results on the braking, steering, and acceleration systems of an automobile. They end by suggesting ways these systems could be made even more robust in future vehicles.

For more information on companies in this article

Related Content

  • In-vehicle systems as enforcement enablers?
    January 30, 2012
    From an enforcement perspective at least, Toyota's recent recalls over problems with accelerator pedal assemblies had a positive outcome in that for the first time a major motor manufacturer outside of the US acknowledged publicly what many have known or suspected for quite a while: that the capability exists within certain car companies to extract data from a vehicle onboard unit which can be used to help ascertain, if not prove outright, just what was happening in the vital seconds up to an accident or cr
  • Internet-connected cars their functionality and safety challenges
    February 27, 2013
    Internet-connected cars are poised to flood the market in the near future. Pete Goldin considers the functionality they offer, the technology they use and the challenge they represent in terms of driver safety. Many vehicles on the road today offer some sort of inter­net connectivity and experts agree that this capability will become a competi­tive differentiator in the automotive industry in the next few years. The era of the digital vehicle, it seems, has started. “We clearly see that cars in the near f
  • Maturing photo enforcement gains legal status, public support
    August 2, 2012
    In the US, affirmation of the photo traffic enforcement sector's legal status and rising public support were significant aspects of 2009. James Tuton, President and CEO of American Traffic Solutions, looks back over the year. In 2009, the photo traffic enforcement industry in North America continued to grow and mature, accompanied by increased public, legislative and legal scrutiny. While public support remains strong, we also saw increased attempts to undermine the industry by representatives of a small bu
  • CVs vulnerable to ‘low skill’ cyberattacks: report
    February 23, 2021
    17% of potential attack scenarios on connected vehicles identified as high-risk, finds Trend Micro