Honda Civics and the Evil Valet

TL;DR

A security researcher has demonstrated a vulnerability in Honda Civic headunits that allows physical attackers, such as valet personnel, to install malicious updates via USB. This flaw, called ‘Evil Valet,’ could enable arbitrary code execution without traditional root access, raising concerns about vehicle security.

A security researcher has revealed a vulnerability in Honda Civic headunits that allows anyone with physical access to install malicious updates via USB, a flaw dubbed ‘Evil Valet.’ This development raises concerns about vehicle security, especially in scenarios involving valet services or theft, as it enables arbitrary code execution on the headunit without conventional root access.

The researcher, who previously reverse-engineered the 2021 Honda Civic headunit, confirmed that the update process relies on signing update files with a publicly-known AOSP test key. By formatting a USB drive with this key, an attacker can stage and install arbitrary updates, including malicious software, on the vehicle’s infotainment system. This process does not require root access but does require physical access to the vehicle’s front USB port.

The attacker could, for example, install a binary with setuid root privileges, effectively taking control of the headunit. The researcher has developed tools to automate the creation of such malicious update files, raising the potential for widespread exploitation if the vulnerability is not patched. Honda has not officially responded to these findings, and it remains unclear whether all models or firmware versions are affected.

Implications for Vehicle Security and User Safety

This vulnerability highlights a significant security gap in modern vehicle infotainment systems, which are increasingly integrated with vehicle controls and sensitive data. If exploited, attackers could potentially manipulate vehicle functions, access personal information, or install persistent malware. The ‘Evil Valet’ attack underscores the importance of securing update mechanisms and physical ports to prevent unauthorized modifications, especially as vehicles become more connected and autonomous.

CARLOCK Anti Theft Car Device - Real Time 4G Car Tracker & Car Alarm System. Comes with Device & Phone App. Tracks Your Car in Real Time & Notifies You Immediately of Suspicious Behavior.OBD Plug&Play

CARLOCK Anti Theft Car Device – Real Time 4G Car Tracker & Car Alarm System. Comes with Device & Phone App. Tracks Your Car in Real Time & Notifies You Immediately of Suspicious Behavior.OBD Plug&Play

WORK & SLEEP WITHOUT WORRY – CarLock anti theft car device and car alarm monitors and alerts you…

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Background on Honda Civic Headunit Security Flaws

Over the past few years, automotive cybersecurity experts have identified vulnerabilities in connected vehicle systems, including infotainment and telematics modules. The 2021 Honda Civic’s headunit, which supports updates via USB, was reverse-engineered by a researcher who discovered that the update process relies on a publicly-known AOSP test key. Previous research has shown that similar systems can be manipulated if update signing is weak or poorly secured. This latest finding builds on that knowledge, demonstrating that physical access combined with knowledge of the update signing process can lead to full system compromise.

While Honda has not issued a formal statement, the researcher’s technical documentation suggests that all updates are signed with the test key, making the system vulnerable if an attacker gains access to the USB port. The researcher also developed tools to help others analyze and craft malicious updates, raising the potential for broader exploitation.

“As long as the headunit has power and an attacker has physical access to the USB port, they can install arbitrary code without needing root access.”

— Researcher

Amazon

Honda Civic headunit security patch

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Extent of Affected Honda Models and Firmware

It is not yet confirmed whether all Honda Civic models or firmware versions are vulnerable. The researcher tested a specific headunit and confirmed the signing process uses the known AOSP test key, but the universality of this flaw across all variants remains unverified. Honda has not issued an official statement clarifying the scope of the vulnerability.

Hacking Connected Cars: Tactics, Techniques, and Procedures

Hacking Connected Cars: Tactics, Techniques, and Procedures

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Potential Patches and User Precautions

Honda may need to update its firmware security measures to prevent unauthorized USB updates. Users are advised to limit physical access to their vehicles’ USB ports and monitor for official security updates. Researchers plan to collaborate with automakers to assess the full scope and develop mitigation strategies. Further technical analysis is expected to clarify the scope of affected models and firmware versions.

USB A Port Blockers 10 Pack, Security Locks with Removal Key, Black

USB A Port Blockers 10 Pack, Security Locks with Removal Key, Black

USB A PORT BLOCKERS WITH KEY: Designed for standard USB A ports on laptops, desktop PCs, notebooks, and…

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

Can this vulnerability be exploited remotely?

No, the ‘Evil Valet’ attack requires physical access to the vehicle’s USB port, such as during valet parking or theft.

Does Honda plan to fix this vulnerability?

There has been no official statement from Honda yet. It is likely they will issue security updates if the vulnerability is confirmed across models.

Is my Honda Civic at risk if I don’t use the USB port?

The vulnerability requires physical access to the USB port. If the port is secure and access is controlled, the risk is minimized.

Could this vulnerability affect other vehicle brands?

Potentially, if other manufacturers use similar update signing mechanisms and allow updates via USB, they could be susceptible as well. Further research is needed.

Source: Hacker News


You May Also Like

The iPhone’s Last Stand?

Apple unveils Siri AI at WWDC 2024, aiming to enhance personal context understanding, but faces challenges against competitors’ AI advancements.

Steam Machine vs Steam Deck: The Real Difference Is Not Just Power

Steam Machine vs Steam Deck explained clearly: power, screen, controls, SteamOS, and which one fits your play style.

Steam Controller Auto-Charge – Pilot To Magnetic Charging Puck Using CV

Valve tests a new auto-charging system for Steam Controllers using a magnetic puck and computer vision technology in a pilot program.

Help if possible connecting quest 3 to steamvr and airlink to horizon link app on pc

Users are exploring ways to connect Quest 3 to SteamVR and Air Link using the Horizon Link app on PC, with some success reported by community members.