| |
A security researcher has discovered a critical vulnerability in 10th-generation Honda Civic infotainment systems, called "EvilValet," which allows arbitrary code execution through the vehicle's USB update port using publicly-known AOSP test keys left in Honda's firmware. The vulnerability enables an attacker with physical access to install malicious software without conventional root access, and the researcher has released tools like ota-builder to demonstrate the exploit and assist in reverse-engineering the system. This represents a significant security flaw that could allow attackers to compromise the vehicle's headunit if they gain brief physical access.
Read Full Article →
← More Tech news