A security researcher discovered a vulnerability in 2021 Honda Civic headunits that allows arbitrary code execution by exploiting the vehicle's USB-based Android Open Source Project update process.
Key Points
- The "EvilValet" vulnerability allows attackers with physical access to the vehicle's USB port to install unauthorized software.
- Honda’s update system relies on a publicly known AOSP test key, enabling the installation of custom firmware without requiring root access.
- New open-source tools, including
ota-builderandapk-rebuilder, have been released to help researchers automate the analysis and modification of headunit update files. - The researcher is calling for community contributions to map software versions and improve tools for parsing AIDL interfaces on the infotainment system.