Skip to main content

Jeep, Dodge, Chrysler maker recalls 1.4 million vehicles amid car hacking fears

Jeep parent company FCA has issued a recall of 1.4 million cars — including such popular vehicles as the Jeep Cherokee, Dodge Charger, and Chrysler 200 — following revelations that hackers can take over a multitude of car functions, including disabling the brakes and engine.

In an article posted on Wired, software engineers Charlie Miller and Chris Valasek demonstrated the ability to remotely access a Cherokee and take over a variety of features, including those key parts of  driving via a vulnerability in the Uconnect infotainment system. This provides many internet-based services by way of a cellular connection. FCA initially released a statement playing down concerns and distributing a software update to plug the proverbial hole; On Friday the company expanded that action to a voluntary safety recall.

Recommended Videos

“FCA U.S. has applied network-level security measures to prevent the type of remote manipulation demonstrated in a recent media report. These measures – which required no customer or dealer actions – block remote access to certain vehicle systems and were fully tested and implemented within the cellular network on July 23, 2015,” says FCA’s recall announcement. This action coincides with the voluntary recall in which the initially released software patch will be installed.

Ron Montoya, senior consumer advice editor at Edmunds.com reached out to Digital Trends on Wednesday when the patch was initially released to explain why drivers need not panic.

“Car owners might read about this hack and become understandably concerned, but they need to know that this is not an issue that should keep them up at night,” Montoya adds. “This week’s hack was an isolated incident that was performed on one specific vehicle and it was not something that could be replicated on a mass scale. Nevertheless, automakers recognize this as a very important issue and they’re proactively working to identify flaws in their own connected systems and address whatever issues they may find.”

jeep-interior
Image used with permission by copyright holder

Montoya also expanded on FCA’s statement that the cyber security breach “required unique and extensive technical knowledge, prolonged physical access to a subject vehicle, and extended periods of time to write code.”

“It’s important to note that these weren’t any old hackers, this was a team that had a grant from DARPA assigned to find vulnerabilities in vehicles,” he said. Miller –a former NSA hacker — and Valasek — director of vehicle security research at the consultancy IOActive — had to start physically tearing though at least 24 cars of various brands before determining that the Jeep Cherokee was the easiest nut to crack. The message here is that considerable time, money, and resources were required to pull off this wireless feat.

In other words, the likelihood of Johnny Anyhacker wantonly overriding vehicles is unlikely. But should we rest easy? Ron suggests that while we can sleep soundly, it’s automakers that should be taking note and stepping up their game. “[Cybersecurity] is something they already keep in mind, but this is something that makes automakers more aware,” he says.

Miller and Valasek will release part of their hacking software for peer review, and FCA isn’t too crazy about that.

“Under no circumstances does FCA condone or believe it’s appropriate to disclose ‘how-to information’ that would potentially encourage, or help enable hackers to gain unauthorized and unlawful access to vehicle systems,” reads a statement from the automaker. The brand further assuages fears stating that “After becoming aware of the vulnerabilities… FCA U.S. and several suppliers worked to fix the vulnerabilities in model year 2015 vehicles. FCA also created a software update that eliminates the vulnerabilities uncovered by Miller and Valasek in their laboratory tests.”

This is something the automaker also wants to make clear: “To FCA’s knowledge, there has not been a single real world incident of an unlawful or unauthorized remote hack into any FCA vehicle” (emphasis theirs).

FCA has also expanded the list of cars subject to the vulnerability. They now include:

  • 2013-15 Dodge Viper specialty vehicles
  • 2013-15 Ram 1500, 2500 and 3500 pickups
  • 2013-15 Ram 3500, 4500, 5500 Chassis Cabs
  • 2014-15 Jeep Grand Cherokee and Cherokee SUVs
  • 2014-15 Dodge Durango SUVs
  • 2015 Chrysler 200, Chrysler 300 and Dodge Charger sedans
  • 2015 Dodge Challenger sports coupes

“It’s important to reiterate that there is no real safety threat to FCA owners,” Montoya concludes. “Earlier this week we installed that patch to our own 2014 Ram 1500,” demonstrating the ease of which the patch can be updated. Owners of any FCA vehicles are still encouraged to go to this link and run their car’s VIN number to check if it falls under the recall.

Alexander Kalogianni
Former Digital Trends Contributor
Alex K is an automotive writer based in New York. When not at his keyboard or behind the wheel of a car, Alex spends a lot of…
The UK’s Wayve brings its AI automated driving software to U.S. shores
wayve ai automated driving us driver assist2 1920x1152 1

It might seem that the autonomous driving trend is moving at full speed and on its own accord, especially if you live in California.Wayve, a UK startup that has received over $1 billion in funding, is now joining the crowded party by launching on-road testing of its AI learning system on the streets of San Francisco and the Bay Area.The announcement comes just weeks after Tesla unveiled its Robotaxi at the Warner Bros Studios in Burbank, California. It was also in San Francisco that an accident last year forced General Motors’ robotaxi service Cruise to stop its operations. And it’s mostly in California that Waymo, the only functioning robotaxi service in the U.S., first deployed its fleet of self-driving cars. As part of its move, Wayve opened a new office in Silicon Valley to support its U.S. expansion and AI development. Similarly to Tesla’s Full-Self Driving (FSD) software, the company says it’s using AI to provide automakers with a full range of driver assistance and automation features.“We are now testing our AI software in real-world environments across two continents,” said Alex Kendall, Wayve co-founder and CEO.The company has already conducted tests on UK roads since 2018. It received a huge boost earlier this year when it raised over $1 billion in a move led by Softbank and joined by Microsoft and Nvidia. In August, Uber also said it would invest to help the development of Wayve’s technology.Just like Tesla’s FSD, Wayve’s software provides an advanced driver assistance system that still requires driver supervision.Before driverless vehicles can legally hit the road, they must first pass strict safety tests.So far, Waymo’s technology, which relies on pre-mapped roads, sensors, cameras, radar, and lidar (a laser-light radar), is the only of its kind to have received the nod from U.S. regulators.

Read more
Pirelli’s new ‘Cyber Tyre’ could be the next traction control
Red Pagani Utopia Roadster in a spotlight on a white background

If you’ve heard whispers about the “Pirelli Cyber Tyre,” or spotted the news about the Italian manufacturer’s work with Bosch, Pagani, and McLaren, then you may be wondering: What makes the new tire so clever? Smart tires as a concept go back a few years, and Pirelli has a habit of squeezing in tech wherever possible. So, what's different this time?

Well, plenty of drivers know what happens when you hit a patch of ice, or test your luck through a particularly bad downpour. Your vehicle loses grip and unless you have the skills needed to get it back on track, you’re probably going to wind up pitched into a ditch or headed sideways into a tree. Things like stability control and traction control help a lot, but they can’t do much when you do start hydroplaning.

Read more
Scout Motors creates connections with its new electric Terra truck and Traveler SUV
Scout Terra and Traveler driving onto the compass-face stage.

Scout Motors invited roughly 300 people to the hills of Franklin, Tennessee, to reveal the Scout Traveler SUV and Terra truck electric concept vehicles. The automaker brought in journalists such as myself, active lifestyle bloggers, YouTubers, automotive industry analysts, and enthusiasts and fans of the original International Harvester Scout.

Scout Motors calls the new, rugged vehicle the Connection Machine. The reveal event aimed to establish a solid connection between the concept EVs and the attendees. The automaker also used the occasion to announce the immediate ability to reserve a Scout vehicle with a $100 fully refundable deposit.
The Scout legend

Read more