Skip to main content

Hackers wirelessly disable a Jeep Cherokee from 10 miles away with Uconnect

2015 Jeep Cherokee
Image used with permission by copyright holder
The thought of “hackers” being able to shut down cars was confined to the hyperbolic ranting of paranoid technophobes just a few years ago. But with digital control now woven into nearly every automotive system, from in-dash entertainment to engine and braking control, the door for exploitation is open wide. And two software engineers just barged right through it, bringing a Jeep Cherokee to a dead stop right from the comfort of their living room.

Charlie Miller and Chris Valasek reached out to Wired writer Andy Greenberg to demonstrate how in-car connectivity can leave vehicles vulnerable to exploits beyond just messing with the radio. The duo discovered that Uconnect, the cellular-based infotainment system in Fiat-Chrysler vehicles, has a vulnerability that allows unprecedented access to the vehicle.

Anyone with the proper knowhow, software, and the vehicle’s IP address can exploit this and engage in a multitude of attacks. From a laptop miles away, the duo can take over the entertainment system, cranking the radio volume up and displaying images on the dash-mounted LED interface screen. They can even control the wipers and influence the digital gauge cluster.

uconnect-press
FCA’s Uconnect interface Image used with permission by copyright holder

But things get more serious: The engineers can totally kill the engine at slow speeds, or shift the transmission to neutral and leave the engine to rev helplessly, halting the Jeep used in the demonstration. The Jeep Cherokee has an available park-assist system which was also fair game for hacking. Normally, sensors guide servos in the steering wheel into a selected parking spot, but when broken into, the engineers could also take hold of that system too, essentially driving the car themselves. Fortunately for owners, that particular trick seems to work only when the car is in reverse. For now, anyway.

“I’d just stomp on the brakes and get out,” you might say, but the hackers are a step ahead of you there, too. Not only can they engage the door locks, but they can remotely kill the brakes, taking that last shred of control away from the driver.

Miller and Valasek have notified Fiat Chrysler Automobiles (FCA) of the Uconnect vulnerability, and the manufacturer pledges to issue a patch to hopefully plug the hole. They also stress that this is a larger issue all automakers need to be aware of, particularly with the growing trend toward semi-to-fully autonomous systems being developed in passenger cars. Taking control of a car might be the more extreme result of this security hole, but possibly more scary is what can be done without the driver being aware. Breaking into the car’s system reveals the vehicle’s GPS location, as well as the VIN and other user data that could be used in nefarious ways.

“If consumers don’t realize this is an issue, they should, and they should start complaining to carmakers,” Miller says. “This might be the kind of software bug most likely to kill someone.”

Editors' Recommendations

Alexander Kalogianni
Former Digital Trends Contributor
Alex K is an automotive writer based in New York. When not at his keyboard or behind the wheel of a car, Alex spends a lot of…
Mercedes-Benz EQG: range, price, release date, and more
Concept image of the larger electric G-Wagon

The G-Class is going electric. We already knew that Mercedes-Benz was working on an electric, small-size G-Wagon, but it looks like the company is also working on a larger G-Class SUV, in the form of the EQG. In fact, Mercedes has gone as far as to show off a concept version of the off-roader.

While there's much we don't know about what will become the production model of the EQG, Mercedes has also shared a lot about it. Curious about whether the Mercedes-Benz EQG could be the EV for you? Here's everything we know so far.
Design
Fear not -- the EQG will retain many of the design aspects of the G-Class that you already know and love but with a modern face-lift. The EQG will keep the boxy design that gives the G-Class a classic look but with some additional modern styling, at least if the concept version is anything to go by.

Read more
Rivian R2 vs. Kia EV9: battle of affordable electric SUVs
Kia EV9 GT-Line Three Quarters

The long-awaited Rivian R2 has finally been announced, and it's an excellent option for those who want an electric SUV that doesn't completely break the bank. Sure, the R2 isn't cheap -- but it's a whole lot cheaper than most other EVs out there, especially when it comes to SUVs. But Rivian isn't the only company trying to tackle the problem of the budget electric SUV. The Kia EV9 is finally available, and it too offers a modern design and a range of helpful features.

Given the fact that the Rivian R2 and Kia EV9 are two electric SUVs in a similar price range, you might be wondering which is better for your needs. That's why we put the Rivian R2 and the Kia EV9 head-to-head.
Design
Both the Rivian R2 and the Kia EV9 are actual SUVs -- not crossovers pretending to be SUVs, like plenty of other EVs out there. The two vehicles offer big, boxy designs and plenty of interior space, making them excellent options for families or those who need that extra storage.

Read more
Rivian R2 vs R1S: How will Rivian’s cheaper SUV compare?
The front three-quarter view of a 2022 Rivian against a rocky backdrop.

Rivian has finally unveiled the R2, its long-awaited attempt at a more affordable electric SUV. The new vehicle may not be available just yet, but fans of Rivian's design aesthetics and feature set are already looking forward to being able to order the new car. The R2 is targeted at being a more affordable take on the electric SUV and will sit alongside the flagship-tier R1S.

Let's get this out of the way right now: The R1S is most likely going to be a better vehicle than the R2. Rivian isn't replacing the R1S with the R2 — it's releasing the R2 as a more affordable alternative, and there will be some compromises when buying the R2 over the R1S.

Read more