Lune

USENIX Security2026Top-tier venue

BLE Theft Auto: Evaluating the Security of Aftermarket BLE-based Automotive Remote Control Systems

Jerry Yu, Yibo Wei, Sumanth Rao, Mohak Vaswani, Jefferson Chien, Christian Dameff, Nishant Bhaskar, Aaron Schulman

2026Year

Abstract

Vehicles are increasingly remotely controllable from smartphone apps that function like keyfobs: unlocking a vehicle's doors and even starting its engine. These systems use Bluetooth Low Energy (BLE) for offline remote control. However, they do not use BLE's built-in security; instead they use proprietary application-layer protocols, introducing a new attack surface. This is especially concerning for aftermarket BLE remote control systems, because they have not received scrutiny by security researchers. In this paper, we evaluate feasible BLE-based attacks on aftermarket vehicle remote control systems. We discovered six aftermarket BLE remote control systems in use today, and analyzed their application-layer BLE security. We found critical vulnerabilities in three systems, exposing what we estimate to be 1.4 million aftermarket BLE control systems to attack. We show that targeted BLE remote attacks are practical: an attacker can use crowdsourced Bluetooth scanning databases to target specific vehicles with vulnerable systems installed. Our disclosures lead all vendors to patch improved app-layer BLE security into their systems, affecting many vehicle owners that did not even know they had a BLE remote control system installed.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

lune papers fulltext 70b4d8d8-4b0f-4c3a-b2ee-7bfacd65cb45

Builds on9

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines