17 Aug 2026
News

Study Warns Hackers Could Exploit Connected-Car Systems

Written by:
Chris Anderson

Modern cars are increasingly becoming computers on wheels, which is great for streaming, remote functions and over-the-air updates. Less great if someone finds a way to make those computers misbehave.

Earlier this year, researchers at Northeastern University in Boston uncovered security vulnerabilities in the wireless connectivity systems of a 2024 Tesla Model 3 and a Cybertruck, demonstrating that attackers could potentially track vehicles, disrupt communications and interfere with network performance.

Aanjhan Ranganathan, associate professor at Northeastern University (Credit: Alyssa Stone/Northeastern University)


The research
also identified weaknesses affecting the vehicles’ SMS and emergency services, which could potentially be abused to send spam, generate fake alerts or create denial-of-service attacks.

Before every Tesla owner starts eyeing their car suspiciously, though, there’s an important distinction: the researchers don’t believe this is simply a Tesla problem.

The vulnerabilities they identified are largely associated with the cellular modem stack used by the vehicles, including components supplied by Qualcomm and Quectel. And those companies’ technology is used by plenty of other connected-car manufacturers. In other words, Tesla happened to be the car on the operating table.

Tesla’s Cybertruck was one of the vehicles used in the study (Credit: Tesla)


“The problem is pretty much applicable to all modern connected cars,” said Aanjhan Ranganathan, an associate professor at Northeastern University’s Khoury College of Computer Sciences. He conducted the study with Evangelos Bitsikas and Jason Veara, who are cybersecurity and privacy doctoral students.

The team chose Tesla partly because its backend systems were relatively accessible for diagnostics and experimentation compared with those of other manufacturers. Consumer Reports loaned the researchers the two cars for testing.

They subsequently disclosed their findings to Tesla, which reportedly acknowledged that many of the weaknesses originated in the third-party cellular modem stack rather than the vehicle’s own software.

Student Evangelos Bitsikas assesses the vehicles’ 4G LTE capability (Credit: Alyssa Stone/Northeastern University)


The researchers recommend that automakers move towards newer 5G networks, eliminate insecure 2G and 3G fallbacks and bring vehicle systems into line with established cybersecurity standards. For drivers, however, there isn’t exactly a convenient “turn off cellular connectivity and carry on with your day” button. “When you buy a connected car, you’re accepting a cellular connection that you cannot turn off or disable or switch to a preferred network,” Ranganathan said.

That’s increasingly important as manufacturers add more remote features, connected services and software-controlled functions to new vehicles. The more a car depends on a permanent connection, the more important it becomes to make sure that connection is properly secured.

northeastern.edu

related posts