Skip to main content

Hackers wirelessly disable a Jeep Cherokee from 10 miles away with Uconnect

2015 Jeep Cherokee
Image used with permission by copyright holder
The thought of “hackers” being able to shut down cars was confined to the hyperbolic ranting of paranoid technophobes just a few years ago. But with digital control now woven into nearly every automotive system, from in-dash entertainment to engine and braking control, the door for exploitation is open wide. And two software engineers just barged right through it, bringing a Jeep Cherokee to a dead stop right from the comfort of their living room.

Charlie Miller and Chris Valasek reached out to Wired writer Andy Greenberg to demonstrate how in-car connectivity can leave vehicles vulnerable to exploits beyond just messing with the radio. The duo discovered that Uconnect, the cellular-based infotainment system in Fiat-Chrysler vehicles, has a vulnerability that allows unprecedented access to the vehicle.

Recommended Videos

Anyone with the proper knowhow, software, and the vehicle’s IP address can exploit this and engage in a multitude of attacks. From a laptop miles away, the duo can take over the entertainment system, cranking the radio volume up and displaying images on the dash-mounted LED interface screen. They can even control the wipers and influence the digital gauge cluster.

uconnect-press
FCA’s Uconnect interface Image used with permission by copyright holder

But things get more serious: The engineers can totally kill the engine at slow speeds, or shift the transmission to neutral and leave the engine to rev helplessly, halting the Jeep used in the demonstration. The Jeep Cherokee has an available park-assist system which was also fair game for hacking. Normally, sensors guide servos in the steering wheel into a selected parking spot, but when broken into, the engineers could also take hold of that system too, essentially driving the car themselves. Fortunately for owners, that particular trick seems to work only when the car is in reverse. For now, anyway.

“I’d just stomp on the brakes and get out,” you might say, but the hackers are a step ahead of you there, too. Not only can they engage the door locks, but they can remotely kill the brakes, taking that last shred of control away from the driver.

Miller and Valasek have notified Fiat Chrysler Automobiles (FCA) of the Uconnect vulnerability, and the manufacturer pledges to issue a patch to hopefully plug the hole. They also stress that this is a larger issue all automakers need to be aware of, particularly with the growing trend toward semi-to-fully autonomous systems being developed in passenger cars. Taking control of a car might be the more extreme result of this security hole, but possibly more scary is what can be done without the driver being aware. Breaking into the car’s system reveals the vehicle’s GPS location, as well as the VIN and other user data that could be used in nefarious ways.

“If consumers don’t realize this is an issue, they should, and they should start complaining to carmakers,” Miller says. “This might be the kind of software bug most likely to kill someone.”

Alexander Kalogianni
Former Digital Trends Contributor
Alex K is an automotive writer based in New York. When not at his keyboard or behind the wheel of a car, Alex spends a lot of…
Hyundai teases Ioniq 9 electric SUV’s interior ahead of expected launch
hyundai ioniq 9 teaser launch 63892 image1hyundaimotorpresentsfirstlookationiq9embarkingonaneweraofspaciousevdesign

The Ioniq 9, the much anticipated three-row, electric SUV from Hyundai, will be officially unveiled at the Los Angeles Auto Show next week.

Selected by Newsweek as one of America’s most anticipated new vehicles of 2025, the Ioniq 9 recently had its name changed from the Ioniq 7, which would have numerically followed the popular Ioniq 6, to signal the SUV as Hyundai’s new flagship EV model.

Read more
Kia EV5: everything we know so far
Kia EV9 front exterior

Kia is expanding its EV lineup in a big way. The company is currently in the middle of rolling out the EV3, which is now available in Europe and is likely to come to the U.S. next year. Not only that, but it's also prepping the EV4, which it will likely announce more widely in 2025. And it's not stopping there either -- the Kia EV5 is a slightly scaled-back version of the much-loved EV9 SUV, and not only is it a vehicle we're excited about, but it's one that has already launched in Australia.

If the EV5 is anything like the EV9 -- only cheaper -- it'll be an instant success. Curious about whether the EV5 could be your next car? Here's everything we know about the EV5.
Design
Despite the lower number, the Kia EV5 is actually larger than the EV6 crossover — but not quite as large as the EV9 SUV. Kia calls it a “compact SUV” that offersa boxy design that’s similar to the EV9, but with only two rows of seats instead of three.

Read more
Trump administration prepares to end Biden’s EV tax incentive, report says
president biden drives 2022 ford f 150 lightning electric pickup truck prototype visits rouge vehicle center

If you’re looking to buy or lease an electric vehicle (EV) and benefit from the Biden administration’s $7,500 tax incentive, you’d better act soon.

The transition team of the incoming Trump administration is already planning to end the credit, according to a report from Reuters citing sources with direct knowledge of the matter.

Read more