AUTO-UPDATED

10th Gen Honda Civic Updates Are Signed with AOSP Test Keys

A security researcher discovered a vulnerability in 2021 Honda Civic headunits that allows arbitrary code execution by exploiting the vehicle's USB-based Android Open Source Project update process.

Key Points

  • The "EvilValet" vulnerability allows attackers with physical access to the vehicle's USB port to install unauthorized software.
  • Honda’s update system relies on a publicly known AOSP test key, enabling the installation of custom firmware without requiring root access.
  • New open-source tools, including ota-builder and apk-rebuilder, have been released to help researchers automate the analysis and modification of headunit update files.
  • The researcher is calling for community contributions to map software versions and improve tools for parsing AIDL interfaces on the infotainment system.

Why it Matters

This discovery highlights significant security weaknesses in automotive infotainment systems that rely on standard Android update mechanisms. The ability to execute arbitrary code via a simple USB connection poses a potential risk to vehicle data privacy and system integrity.
Juniperspring.org Published by Eric McDonald
Read original