Hacker Finds Data Vulnerability in Subaru Starlink, Enabling Remote Control Without Driver Consent

Jan. 28, 2025
Security researcher and ethical hacker Sam Curry has claimed he discovered a cybersecurity risk in Subaru vehicles, allowing access to sensitive data and functions.

Security researcher and ethical hacker Sam Curry has claimed he discovered a cybersecurity risk in Subaru vehicles, allowing hackers to access data on owners and even remote control functions, reports The Street.

As shared in a Jan. 23 blog post, Curry and an associate were able to access Subaru’s Starlink—which powers vehicle infotainment and different safety features—through a gap in the administrator console. 

It granted them administrative access, allowing them to access the data of nearly every Subaru vehicle in the U.S., Canada, and Japan that has Starlink. By having a Subaru owner’s full name, address, license plate number, or VIN, the location data of a vehicle could be tracked for up to a year.

In addition, Curry found they could enable functions found in the MySubaru app, such as remote locking, unlocking, start-up, and shut down.

To test the limits of this, Curry reached out to a friend of his who owns a Subaru. Through being provided with only the license plate number, Curry was able to make himself an authorized user, allowing him to exert whatever functions he wanted on the car.

“Afterwards, she confirmed that she did not receive any notification, text message, or email after we added ourselves as an authorized user and unlocked her car,” wrote Curry.

Curry said he first discovered the vulnerability in November 2024, after which he made Subaru aware and the issue was patched. However, a representative with Subaru of America told The Street that Curry and his partner “received authorization from their friends and family to access their information,” and that no Starlink customer accounts had actually been compromised.

Regardless, Curry claimed that he’s seen similar data vulnerabilities from other automakers as well, including Acura, Honda, Ferrari, Hyundai, Kia, and Toyota.

About the Author

Ratchet+Wrench Staff Reporters

The Ratchet+Wrench staff reporters have a combined two-plus decades of journalism and mechanical repair experience.

Sponsored Recommendations

Valvoline Partner Solutions

We arm you with products that build trust, tools that unlock productivity, and training that drives business performance, so you feel confident in where your...

Grow the business you know

Enjoy the videos and music you love, upload original content, and share it all with friends, family, and the world on YouTube.

Solutions that drive results

Connect with Valvoline experts to increase operational efficiency and customer loyalty – from Valvoline-funded promotions to hands-on training, we’re here to...

Free Resources for Shops Like Yours

View insights, research and solutions curated specifically for shops like yours.