Skip to main content
  1. Home
  2. Phones
  3. Cars
  4. Mobile
  5. News

Hackers wirelessly disable a Jeep Cherokee from 10 miles away with Uconnect

Add as a preferred source on Google

The thought of “hackers” being able to shut down cars was confined to the hyperbolic ranting of paranoid technophobes just a few years ago. But with digital control now woven into nearly every automotive system, from in-dash entertainment to engine and braking control, the door for exploitation is open wide. And two software engineers just barged right through it, bringing a Jeep Cherokee to a dead stop right from the comfort of their living room.

Charlie Miller and Chris Valasek reached out to Wired writer Andy Greenberg to demonstrate how in-car connectivity can leave vehicles vulnerable to exploits beyond just messing with the radio. The duo discovered that Uconnect, the cellular-based infotainment system in Fiat-Chrysler vehicles, has a vulnerability that allows unprecedented access to the vehicle.

Recommended Videos

Anyone with the proper knowhow, software, and the vehicle’s IP address can exploit this and engage in a multitude of attacks. From a laptop miles away, the duo can take over the entertainment system, cranking the radio volume up and displaying images on the dash-mounted LED interface screen. They can even control the wipers and influence the digital gauge cluster.

uconnect-press
FCA’s Uconnect interface Image used with permission by copyright holder

But things get more serious: The engineers can totally kill the engine at slow speeds, or shift the transmission to neutral and leave the engine to rev helplessly, halting the Jeep used in the demonstration. The Jeep Cherokee has an available park-assist system which was also fair game for hacking. Normally, sensors guide servos in the steering wheel into a selected parking spot, but when broken into, the engineers could also take hold of that system too, essentially driving the car themselves. Fortunately for owners, that particular trick seems to work only when the car is in reverse. For now, anyway.

“I’d just stomp on the brakes and get out,” you might say, but the hackers are a step ahead of you there, too. Not only can they engage the door locks, but they can remotely kill the brakes, taking that last shred of control away from the driver.

Miller and Valasek have notified Fiat Chrysler Automobiles (FCA) of the Uconnect vulnerability, and the manufacturer pledges to issue a patch to hopefully plug the hole. They also stress that this is a larger issue all automakers need to be aware of, particularly with the growing trend toward semi-to-fully autonomous systems being developed in passenger cars. Taking control of a car might be the more extreme result of this security hole, but possibly more scary is what can be done without the driver being aware. Breaking into the car’s system reveals the vehicle’s GPS location, as well as the VIN and other user data that could be used in nefarious ways.

“If consumers don’t realize this is an issue, they should, and they should start complaining to carmakers,” Miller says. “This might be the kind of software bug most likely to kill someone.”

Alexander Kalogianni
Former Automotive Editor
Alex K is an automotive writer based in New York. When not at his keyboard or behind the wheel of a car, Alex spends a lot of…
Cash App now doubles as a phone carrier with a $40 unlimited plan
Your money app is coming for your phone plan next
Cash App Mobile Announcement

Cash App already handles a lot of your finances. From money transfers, debit cards, to investments and even tax filing, the platform does nearly everything. Now, it wants to take over another regular part of your life. The company has announced Cash App Mobile, a new unlimited 5G phone plan priced at $40 per month, with taxes and fees included. It runs on AT&T’s network and is powered by Gigs, a company that helps brands launch embedded mobile services. The plan is launching as a pilot for select Cash App users, with wider availability planned in the coming months.

The app you use to split dinner now wants to run your phone

Read more
Humbling teardown confirms Trump Phone is just a painted-over HTC phone
Electronics, Phone, Mobile Phone

When the Trump Mobile T1 was announced, it arrived wrapped in the kind of marketing language you’d expect from a product tied to Donald Trump: bold claims, patriotic branding, and plenty of references to American values. What wasn’t immediately clear was what made the phone itself special.

Now, thanks to a detailed teardown and CT scan analysis by iFixit, we appear to have an answer. And it’s not exactly the revelation Trump Mobile was probably hoping for. After peeling back the gold-colored exterior, investigators found what looks remarkably like another smartphone already on the market: HTC’s U24 Pro. That’s awkward for a device marketed as something distinct.

Read more
Saily just turned the eSIM into a $1 burner phone number
NordVPN’s eSIM app could save your real phone number from app spam
Saily eSIM now offers $1 Burner Number

If you're like me and have relied on travel eSIMs, you know the drill. You get access to mobile data abroad without paying the premium your carrier charges for the roaming bill. But more often than not, you're stuck with just data since you don't actually have a proper phone number to use.

But Saily is trying to make traveler eSIMs a lot more useful by actually including a phone number. NordVPN's eSIM app is now letting users get a dedicated US +1 phone number directly through the Saily app. The number subscription starts at $0.99 per month, with separate call and text plans also starting from $0.99. So, for less than a cup of coffee, you get a second number that can be handy for food delivery apps, hotel bookings, ticketing services, online marketplaces, 2FA codes, and all those random forms that ask for your phone number.

Read more