Technology NewsTechnology NewsTechnology News
  • Computing
  • AI
  • Robotics
  • Cybersecurity
  • Electric Vehicle
  • Wearables
  • Gaming
  • Space
Reading: Researchers Expose Remote Code Threat in Major Car Bluetooth Systems
Share
Font ResizerAa
Technology NewsTechnology News
Font ResizerAa
Search
  • Computing
  • AI
  • Robotics
  • Cybersecurity
  • Electric Vehicle
  • Wearables
  • Gaming
  • Space
Follow US
  • Cookie Policy (EU)
  • Contact
  • About
© 2025 NEWSLINKER - Powered by LK SOFTWARE
Electric Vehicle

Researchers Expose Remote Code Threat in Major Car Bluetooth Systems

Highlights

  • The PerfektBlue vulnerabilities affect millions of cars using OpenSynergy BlueSDK.

  • Attackers need Bluetooth proximity and pairing to exploit and run remote code.

  • Patch rollout remains slow, highlighting ongoing automotive supply chain issues.

Ethan Moreno
Last updated: 11 July, 2025 - 7:50 pm 7:50 pm
Ethan Moreno 20 hours ago
Share
SHARE

Security concerns in the automotive industry continue to grow as more vehicles integrate advanced connectivity features. As carmakers pursue seamless digital experiences, new vulnerabilities gain the potential to affect not only individual vehicles but also millions of users worldwide. Recent findings illustrate how infotainment systems, designed for convenience, can introduce unseen points of entry for cyber attackers, raising questions about the interplay between innovation, user safety, and rapid response from industry stakeholders.

Contents
Which Vehicles Face the Highest Risk?How Could Attackers Gain Access to Vehicle Systems?What Is the Impact of These Bluetooth Vulnerabilities?

Earlier public discussions of automotive cybersecurity focused on theoretical risks and isolated incidents, often involving remote keyless entry or Wi-Fi connectivity. Past reports centered on vulnerabilities in proprietary systems or less widely adopted platforms, with rapid patch deployment generally addressing exposures. The large number of vehicles using the OpenSynergy BlueSDK framework marks a departure from previous cases, with multiple well-known brands now simultaneously affected. Delayed patch distribution reported here suggests an emerging pattern of complex supply chain hurdles unique to automotive technology.

Which Vehicles Face the Highest Risk?

OpenSynergy’s BlueSDK Bluetooth stack is widely used in embedded automotive systems and is present in Mercedes-Benz, Volkswagen, and Skoda models. A fourth car manufacturer utilizing this technology remains unnamed by researchers. Specific systems affected include the Mercedes-Benz NTG6 infotainment unit, Volkswagen’s MEB ICAS3 module used in electric .ID vehicles, and Skoda’s MIB3 system found in its Superb lineup.

How Could Attackers Gain Access to Vehicle Systems?

To exploit these vulnerabilities—collectively named PerfektBlue—an attacker must be within Bluetooth range and achieve successful pairing with a vehicle’s infotainment interface. The pairing process varies according to each manufacturer’s configuration of BlueSDK, with some setups requiring user approval and others allowing easier connections. When these four security flaws are chained, unauthorized access to the infotainment operating system becomes possible.

What Is the Impact of These Bluetooth Vulnerabilities?

The risks relate chiefly to remote code execution on targeted vehicles, enabling potential access to sensitive data and vehicle interfaces. Researchers demonstrated this through proof-of-concept attacks, achieving reverse shell access on infotainment units. Key vulnerabilities involve a critical use-after-free issue in the AVRCP service (CVE-2024-45434, CVSS 8.0) and weaknesses in Bluetooth protocol handling within L2CAP and RFCOMM. Opportunities for lateral movement inside vehicle networks depend on manufacturers’ security architecture and network segmentation.

Patch management remains a persistent challenge. Although OpenSynergy developed fixes by September 2024—following initial reports in May—the process of updating affected vehicles has been hindered by supply chain complexity. As of June 2025, some manufacturers had not received updated code. Researchers have chosen to publicly disclose the vulnerabilities to urge more rapid remediation across the sector, while withholding specific details about the unnamed fourth manufacturer.

Automotive cybersecurity incidents underscore the need for rigorous ongoing monitoring of connected vehicle components. The presence of Bluetooth vulnerabilities in systems from Mercedes-Benz, Volkswagen, and Skoda demonstrates how integration of shared software stacks can create industry-wide exposure. For consumers, keeping infotainment and vehicle firmware up to date is crucial. For manufacturers, tightening separation between infotainment and critical subsystems, deploying regular security audits, and working closely with software providers are vital steps. As vehicles grow more connected, proactive vulnerability handling and transparency regarding security flaws are increasingly essential to reduce risk across diverse fleets.

You can follow us on Youtube, Telegram, Facebook, Linkedin, Twitter ( X ), Mastodon and Bluesky

You Might Also Like

Canadian Officials Clear Tesla in Zero-Emission Vehicle Rebate Probe

Tesla Installs 18 New Megachargers at PepsiCo’s Charlotte Facility

Tesla Drives Sales Growth in Norway With Model Y Surge

Tesla Launches Its Debut Showroom in Mumbai, Expands Indian Presence

Tesla Pursues Robotaxi Certification and Plans Bay Area Expansion

Share This Article
Facebook Twitter Copy Link Print
Ethan Moreno
By Ethan Moreno
Ethan Moreno, a 35-year-old California resident, is a media graduate. Recognized for his extensive media knowledge and sharp editing skills, Ethan is a passionate professional dedicated to improving the accuracy and quality of news. Specializing in digital media, Moreno keeps abreast of technology, science and new media trends to shape content strategies.
Previous Article AI Drives Major Shifts Across Insurance Operations and Customer Service
Next Article Cadence Faces Stiffer Competition as Semiconductor Standing Declines

Stay Connected

6.2kLike
8kFollow
2.3kSubscribe
1.7kFollow

Latest News

Players Tackle Wordle’s Latest Challenge With Fresh Strategies
Gaming
Supply Chain Robotics Experts Address Industry Setbacks and Progress
AI Robotics
Kraken Robotics Secures $115M to Boost Marine Systems Expansion
Robotics
Toyota Research Institute Boosts Robot Learning with Large Behavior Models
AI
Hugging Face Rolls Out Reachy Mini for AI Robotics Enthusiasts
AI
NEWSLINKER – your premier source for the latest updates in ai, robotics, electric vehicle, gaming, and technology. We are dedicated to bringing you the most accurate, timely, and engaging content from across these dynamic industries. Join us on our journey of discovery and stay informed in this ever-evolving digital age.

ARTIFICAL INTELLIGENCE

  • Can Artificial Intelligence Achieve Consciousness?
  • What is Artificial Intelligence (AI)?
  • How does Artificial Intelligence Work?
  • Will AI Take Over the World?
  • What Is OpenAI?
  • What is Artifical General Intelligence?

ELECTRIC VEHICLE

  • What is Electric Vehicle in Simple Words?
  • How do Electric Cars Work?
  • What is the Advantage and Disadvantage of Electric Cars?
  • Is Electric Car the Future?

RESEARCH

  • Robotics Market Research & Report
  • Everything you need to know about IoT
  • What Is Wearable Technology?
  • What is FANUC Robotics?
  • What is Anthropic AI?
Technology NewsTechnology News
Follow US
About Us   -  Cookie Policy   -   Contact

© 2025 NEWSLINKER. Powered by LK SOFTWARE
Welcome Back!

Sign in to your account

Register Lost your password?