Researchers discovered critical vulnerabilities, named PerfektBlue, in OpenSynergy BlueSDK Bluetooth stack, which could lead to remote code execution in millions of vehicles' systems.
The vulnerabilities could allow attackers to hack into car infotainment systems remotely, potentially enabling access to sensitive data and control over functions like location tracking and audio recording.
The OpenSynergy BlueSDK Bluetooth framework, widely used in automotive applications, is found in vehicles from vendors like Mercedes-Benz, Volkswagen, and Skoda.
Affected vendors have received patches to address the vulnerabilities, and responsible disclosure was conducted to raise awareness and encourage timely remediation within the automotive industry.