USENIX Security2026Top-tier venue
BLE Theft Auto: Evaluating the Security of Aftermarket BLE-based Automotive Remote Control Systems
Jerry Yu, Yibo Wei, Sumanth Rao, Mohak Vaswani, Jefferson Chien, Christian Dameff, Nishant Bhaskar, Aaron Schulman
Abstract
Vehicles are increasingly remotely controllable from smartphone apps that function like keyfobs: unlocking a vehicle's doors and even starting its engine. These systems use Bluetooth Low Energy (BLE) for offline remote control. However, they do not use BLE's built-in security; instead they use proprietary application-layer protocols, introducing a new attack surface. This is especially concerning for aftermarket BLE remote control systems, because they have not received scrutiny by security researchers. In this paper, we evaluate feasible BLE-based attacks on aftermarket vehicle remote control systems. We discovered six aftermarket BLE remote control systems in use today, and analyzed their application-layer BLE security. We found critical vulnerabilities in three systems, exposing what we estimate to be 1.4 million aftermarket BLE control systems to attack. We show that targeted BLE remote attacks are practical: an attacker can use crowdsourced Bluetooth scanning databases to target specific vehicles with vulnerable systems installed. Our disclosures lead all vendors to patch improved app-layer BLE security into their systems, affecting many vehicle owners that did not even know they had a BLE remote control system installed.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 70b4d8d8-4b0f-4c3a-b2ee-7bfacd65cb45Builds on9
- Lock It and Still Lose It - on the (In)Security of Automotive Remote Keyless Entry SystemsFlavio D. Garcia, David F. Oswald, Timo Kasper, Pierre PavlidèsUSENIX Security 2016 · 151 citations
- Automatic Fingerprinting of Vulnerable BLE IoT Devices with Static UUIDs from Mobile AppsChaoshun Zuo, Haohuang Wen, Zhiqiang Lin, Yinqian ZhangCCS 2019 · 77 citations
- A Study of the Feasibility of Co-located App Attacks against BLE and a Large-Scale Analysis of the Current Application-Layer Security LandscapePallavi Sivakumaran, Jorge BlascoUSENIX Security 2019 · 42 citations
- Method Confusion Attack on Bluetooth PairingMaximilian von Tschirschnitz, Ludwig Peuckert, Fabian Franzen, Jens GrossklagsS&P 2021 · 42 citations
- Please Pay Inside: Evaluating Bluetooth-based Detection of Gas Pump SkimmersNishant Bhaskar, Maxwell Bland, Kirill Levchenko, Aaron SchulmanUSENIX Security 2019 · 12 citations
Related papers
- Cloud-Native Carjacking: Fleet-wide Compromise via Telematics Authorization FailuresYangyang Liu, Zhengjie Du, Xiaofang Wang, Yang Yin et al.USENIX Security 2026
- BLESS: A BLE Application Security Scanning FrameworkYue Zhang, Jian Weng, Zhen Ling, Bryan Pearson et al.INFOCOM 2020 · 15 citations
- Plug-N-Pwned: Comprehensive Vulnerability Analysis of OBD-II Dongles as A New Over-the-Air Attack Surface in Automotive IoTHaohuang Wen, Qi Alfred Chen, Zhiqiang LinUSENIX Security 2020
- Evaluating Physical-Layer BLE Location Tracking Attacks on Mobile DevicesHadi Givehchian, Nishant Bhaskar, Eliana Rodriguez Herrera, Héctor Rodrigo López Soto et al.S&P 2022 · 55 citations
- Linking Bluetooth LE & Classic and Implications for Privacy-Preserving Bluetooth-Based ProtocolsNorbert Ludant, Tien Dang Vo-Huu, Sashank Narain, Guevara NoubirS&P 2021 · 11 citations
