A researcher published an update on reverse-engineering Honda Civic infotainment systems, discovering a vulnerability called "EvilValet" that allows arbitrary code execution through USB updates using publicly-known Android test keys. The researcher released tools like ota-builder and apk-rebuilder to facilitate analysis and is seeking contributors to document software versions and improve related development tooling.
1 comment
A researcher published an update on reverse-engineering Honda Civic infotainment systems, discovering a vulnerability called "EvilValet" that allows arbitrary code execution through USB updates using publicly-known Android test keys. The researcher released tools like ota-builder and apk-rebuilder to facilitate analysis and is seeking contributors to document software versions and improve related development tooling.