Lune

S&P2026Top-tier venue

BACHunter: Detecting Broken Access Control Vulnerabilities in Intelligent Connected Vehicles

Yanbang Sun, Xiaohong Li, Quanzhou Wang, Hebo Leng, Guangzheng Yao, Zhihua Xie, Qiang Hu, Junjie Wang

2026Year

Abstract

Intelligent Connected Vehicles (ICVs) have become an essential part of modern transportation systems, leading to a high demand for safeguarding their security and safety. Among the security concerns, Broken-Access-Control (BAC) vulnerabilities in ICV cloud platforms enable attackers to gain unauthorized remote access to vehicle, thereby compromising user privacy and security, and posing one of the most significant issues to be addressed. However, existing methods cannot effectively detect BAC vulnerabilities due to their inaccurate attack surface identification and invalid attack payload construction, highlighting more advanced solutions in this domain. To address these challenges, we introduce BACHunter, a black-box vulnerability detection method specifically designed for ICV cloud platforms. Specifically, BACHunter first identifies attack surfaces through Large Language Model (LLM) powered semantic modeling for cloud platform Application Programming Interfaces (APIs), and then reconstructs the generation logic of validation fields based on ICV client disassembled code to construct effective attack payloads. Finally, BACHunter detects BAC vulnerabilities by comparing the responses of normal requests with those of the attack payloads. Through the evaluation of 10 ICVs from 6 automotive manufacturers, BACHunter successfully discovers 84 confirmed 0\mathbf{0}-day vulnerabilities and significantly outperforms state-of-theart methods such as BACDetector and BACScan. All newly discovered vulnerabilities have been reported to the affected automotive manufacturers. To date, 73 vulnerabilities have been fixed, and 49 CAVD (China Automobile Vulnerability Database) IDs have been assigned. Further in-depth analysis indicates that BAC vulnerabilities are a systemic security issue in the ICV industry, primarily caused by the failure to verify the relationship between user identities and target resources. Based on these insights, we provide potential defense recommendations, focusing on strict server-side authorization checks, enhanced data protection, and reverse engineering defenses.

Ask about this paper

Ask your agent about it.

Lune has read the top-tier papers around this one, so every answer names the papers it rests on.

Questions to start from

Your agent calls

Lunesearch_papers

Ask in Lune

Free to start. No credit card required.

lune papers get ed1aabcd-8def-4308-abfc-133dc8f72ae8

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines