USENIX Security2026Top-tier venue
Cloud-Native Carjacking: Fleet-wide Compromise via Telematics Authorization Failures
Yangyang Liu, Zhengjie Du, Xiaofang Wang, Yang Yin, Xiapu Luo
Abstract
Modern connected vehicles increasingly rely on cloud-centric telematics backends to provide remote control, telemetry, media access, and other software-defined functionality. Although these platforms commonly employ endpoint hardening and encrypted communication, such measures do not ensure correct backend authorization. Across the platforms we evaluated, cloud services often accepted a valid vehicle identity without consistently binding that identity to the specific topic, object, or command target being accessed. We investigate this failure mode by recovering reusable authentication material from a seed vehicle and testing whether backend authorization remains properly scoped to vehicle-specific resources across MQTT, HTTPS, and SMS. On several legacy platforms, process-memory inspection exposed client certificates, private keys, tokens, or session artifacts sufficient to authenticate to backend services. Using this material, we established authenticated backend sessions and then modified logical vehicle identifiers, such as Vehicle Identification Numbers (VINs), at the application layer. We discovered previously unknown authorization vulnerabilities in telematics platforms used by three major OEMs. Starting from a single seed vehicle under the attacker's control, we demonstrate cross-vehicle privilege escalation without physical access to victim vehicles and without OEM-internal privileges. These flaws enable remote vehicle control, unauthorized access to private surveillance media, and spoofed fallback commands. We conclude with root-cause analysis informed by coordinated disclosure and derive mitigation lessons for identity-bound, Zero-Trust-style telematics authorization.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on8
- Lock It and Still Lose It - on the (In)Security of Automotive Remote Keyless Entry SystemsFlavio D. Garcia, David F. Oswald, Timo Kasper, Pierre PavlidèsUSENIX Security 2016 · 151 citations
- Too Good to Be Safe: Tricking Lane Detection in Autonomous Driving with Crafted PerturbationsPengfei Jing, Qiyi Tang, Yuefeng Du, Lei Xue et al.USENIX Security 2021 · 79 citations
- CANflict: Exploiting Peripheral Conflicts for Data-Link Layer Attacks on Automotive NetworksAlvise de Faveri Tron, Stefano Longari, Michele Carminati, Mario Polino et al.CCS 2022 · 21 citations
- Revisiting Automotive Attack Surfaces: a Practitioners' PerspectivePengfei Jing, Zhiqiang Cai, Yingjie Cao, Le Yu et al.S&P 2024 · 16 citations
- ERACAN: Defending Against an Emerging CAN Threat ModelZhaozhou Tang, Khaled Serag, Saman A. Zonouz, Z. Berkay Celik et al.CCS 2024 · 5 citations
Related papers
- BLE Theft Auto: Evaluating the Security of Aftermarket BLE-based Automotive Remote Control SystemsJerry Yu, Yibo Wei, Sumanth Rao, Mohak Vaswani et al.USENIX Security 2026
- BACHunter: Detecting Broken Access Control Vulnerabilities in Intelligent Connected VehiclesYanbang Sun, Xiaohong Li, Quanzhou Wang, Hebo Leng et al.S&P 2026
- Shadow Tokens: Uncovering the Broken Permission Revocation Vulnerability in Intelligent Connected VehiclesYanbang Sun, Hebo Leng, Qiang Hu, Xiaofei Xie et al.CCS 2026
- Head Unit at Risk: Cross-Domain Attacks via In-Vehicle Infotainment SystemsYanbo Xu, Yan Meng, Guoxing Chen, Haojin ZhuCCS 2026
- SECV: Securing Connected Vehicles with Hardware Trust AnchorsMartin Kayondo, Junseung You, Eunmin Kim, Jiwon Seo et al.NDSS 2026 · 1 citation
