IVI systems

How Subaru’s IVI System Admin Panel Vulnerability Could Have Enabled Vehicle Tracking and Control

How Subaru’s IVI System Admin Panel Vulnerability Could Have Enabled Vehicle Tracking and Control

Security researchers uncovered a vulnerability in Subaru’s in-vehicle infotainment (IVI) system admin panel, enabling unauthorized access to personal information, GPS records, and vehicle controls. We examine the findings and emphasize the need for automotive manufacturers to adopt a security-first approach throughout the vehicle lifecycle.

From Pwn2Own Automotive: A High-Severity Zero-Click RCE Bluetooth Vulnerability in the Alpine Halo9 IVI System

From Pwn2Own Automotive: A High-Severity Zero-Click RCE Bluetooth Vulnerability in the Alpine Halo9 IVI System

The Pwn2Own Automotive 2024 competition uncovered a high-severity zero-click RCE Bluetooth vulnerability in the Alpine Halo9 IVI system, highlighting the risks of proprietary implementations in connected vehicles. We explore the discovery, exploitation techniques, and key takeaways for securing automotive technologies against emerging threats.