Full Report
Modern connected cars, particularly EVs and hybrids, are increasingly run by software, giving manufacturers the power to change, update and control vehicles, like never before. In the case of BYD and others, that software is controlled from China. With fuel prices on the rise, EVs and plug-in hybrids like the Shark have gone mainstream this…
Analysis Summary
# Vulnerability: Remote Vehicle Control and Surveillance in BYD Connected Vehicles
## CVE Details
- **CVE ID:** Not explicitly assigned in the provided text (Research conducted by third-party experts).
- **CVSS Score:** N/A (Based on description, likely **Critical**).
- **CWE:** CWE-287 (Improper Authentication) / CWE-912 (Managed Backdoor) – inferred from remote control capabilities described.
## Affected Systems
- **Products:** BYD Electric Vehicles (EVs) and Plug-in Hybrids.
- **Versions:** Current production models (specifically mentions the **BYD Shark**).
- **Configurations:** Vehicles with active internet connectivity and Chinese-managed software stacks.
## Vulnerability Description
The flaw involves the ability for unauthorized remote access to the vehicle's core software systems. Because the vehicle’s software ecosystem is centralized and controlled by the manufacturer (specifically via infrastructure located in China), security experts demonstrated that they could bypass security measures to gain control over vehicle functions. This includes the potential for vehicle sabotage and unauthorized surveillance through integrated hardware.
## Exploitation
- **Status:** PoC demonstrated by cybersecurity experts (as reported by ABC News).
- **Complexity:** Low (Described as "too easy" by the performing expert).
- **Attack Vector:** Network (Remote via cellular/internet connectivity).
## Impact
- **Confidentiality:** **High** (Capability for driver surveillance and data harvesting).
- **Integrity:** **High** (Capability to change, update, or control vehicle software/mechanics remotely).
- **Availability:** **High** (Potential for vehicle sabotage or "bricking" the car).
## Remediation
### Patches
- No specific patch version is listed in the source. As these are software-defined vehicles, updates are typically delivered Over-the-Air (OTA) by BYD.
### Workarounds
- Information regarding specific user-level workarounds is not provided. General mitigation for connected vehicles involves limiting app permissions and disabling unnecessary connectivity features where possible.
## Detection
- **Indicators of Compromise:** Unusual data outbound traffic to unrecognized foreign IP addresses; unauthorized OTA updates; unexpected activation of vehicle hardware (cameras/microphones).
- **Detection Methods and Tools:** Network traffic analysis of the vehicle’s eSIM/Wi-Fi communication; monitoring for unauthorized changes in vehicle firmware.
## References
- ABC News Original Report: [https://www.abc.net.au/news/2026-09-21/byd-hacked-by-cybersecurity-expert-vehicle-sabotage-surveillance/107139482]
- Threat Beat Summary: [https://threatbeat.com/threats/we-got-a-cybersecurity-expert-to-hack-this-byd-it-was-too-easy/]