Android Malware Used To Hack and Steal Tesla Car

0
526

An anonymous reader writes: By leveraging security flaws in the Tesla Android app, an attacker can steal Tesla cars. The only hard part is tricking Tesla owners into installing an Android app on their phones, which isn’t that difficult according to a demo video from Norwegian firm Promon. This malicious app can use many of the freely available Android rooting exploits to take over the user’s phone, steal the OAuth token from the Tesla app and the user’s login credentials. This is possible because the Tesla Android app stores the OAuth token in cleartext, and contains no reverse-engineering protection, allowing attackers to alter the app’s source code and log user credentials. The OAuth token and Tesla owner’s password allow an attacker to perform a variety of actions, such as opening the car’s doors and starting the motor. Read more of this story at Slashdot.

Read the article:
Android Malware Used To Hack and Steal Tesla Car

LEAVE A REPLY

Please enter your comment!
Please enter your name here

*

This site uses Akismet to reduce spam. Learn how your comment data is processed.