Researchers disclosed a critical flaw in Subaru’s STARLINK connected vehicle platform that allowed takeover of an employee-facing admin portal and unrestricted access to customer accounts in the United States, Canada, and Japan. The attack chain reportedly combined an unauthenticated password-reset endpoint, user enumeration, and a client-side-only two-factor authentication barrier that could be bypassed, enabling attackers to look up drivers using identifiers such as name and ZIP code, email address, phone number, VIN, or a VIN derived from a license plate.
With admin access, an attacker could remotely perform actions including locking or unlocking doors, starting or stopping supported vehicles, adding themselves as an authorized user, and tracking a car’s real-time and historical location data for up to a year. The exposed records also included PII, emergency contacts, billing-related details, vehicle PINs, support history, odometer readings, prior ownership, and sales history; researchers demonstrated unlocking a friend’s Subaru without any user notification. Subaru said it patched the issue within 24 hours of disclosure, and the researchers reported no evidence of malicious exploitation.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Researchers publicly disclosed a critical vulnerability in Subaru's connected vehicle service that exposed customer data and enabled remote vehicle actions in the United States, Canada, and Japan. The disclosure detailed the insecure password reset flow, user enumeration, and bypassable client-side 2FA protections.
After the researchers disclosed the STARLINK Admin Portal vulnerability to Subaru, the company responded and fixed the affected system within 24 hours. The reporting states the issue was not maliciously exploited.
As of 2024-11-20, researchers found Subaru's STARLINK Admin Portal flaws allowed takeover of an employee account, access to customer and vehicle data, and remote actions against vehicles. They demonstrated the impact by adding themselves as an authorized user on a friend's Subaru and remotely unlocking it without notifying the victim.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.