Honda Civics and the Evil Valet

TL;DR

A security researcher has demonstrated that Honda Civic headunits are vulnerable to an ‘Evil Valet’ attack, where physical access via USB allows installing malicious updates. This could enable unauthorized control of vehicle systems.

A security researcher has demonstrated a method to exploit a vulnerability in Honda Civic headunits, allowing malicious software installation through physical access via USB, dubbed the ‘Evil Valet’ attack. This exposes a significant security risk, especially in scenarios where attackers or insiders can access the vehicle’s USB port without detection.

The researcher, who has been studying the 2021 Honda Civic headunit, confirmed that the update process relies on signing update files with a publicly-known AOSP test key. By formatting a USB drive and signing it with this key, an attacker can stage and install arbitrary code on the headunit, bypassing conventional security checks. This process does not require root access but does need physical access to the vehicle’s front USB port.

The attack, termed ‘Evil Valet’ by the researcher, is akin to an ‘evil maid’ attack but occurs in the context of a valet service. An attacker working for a three-letter agency or malicious actor could leave a vehicle at a hotel, insert a malicious update via USB, and return the vehicle unaware of the compromise. Once the update is installed, malicious code could persist, potentially gaining control over vehicle functions or installing persistent malware.

The researcher has also developed a tool called ota-builder, which simplifies creating such malicious updates, and apk-rebuilder, which reverse engineers Honda update files to understand their structure. While the researcher has not confirmed whether all Honda updates are signed with the test key, evidence suggests they are, which makes the vulnerability widespread across many vehicles.

Potential Security Risks for Honda Civic Owners

This vulnerability highlights a significant security concern for Honda Civic owners and potentially other vehicles with similar update mechanisms. Physical access to the vehicle’s USB port could enable malicious actors to install malware or modify system software without detection, raising risks of remote control, data theft, or other malicious activities. The attack’s simplicity and reliance on known keys make it a pressing issue for automotive cybersecurity.

Amazon

Honda Civic headunit USB security lock

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Background on Honda Civic Headunit Security Flaws

The Honda Civic headunit has supported firmware updates via USB for several years, with the process involving signed update files. A researcher previously reverse-engineered the update process, discovering that Honda signs updates with a publicly-known AOSP test key. This flaw allows unsigned or malicious updates to be staged and installed if the attacker can physically access the vehicle’s USB port. The researcher’s work builds on prior efforts to understand and manipulate automotive infotainment systems, emphasizing the potential for hardware-based attacks in modern vehicles.

“As long as you can properly format a USB drive and sign it with the publicly-known AOSP test key, you can install whatever you want to the headunit.”

— Researcher

Scope and Widespread Nature of the Vulnerability

While the researcher believes that all Honda updates are signed with the AOSP test key, it is not confirmed whether this applies universally across all Honda models and regions. The full extent of affected vehicles, especially those with different firmware versions or security configurations, remains unclear. Additionally, it is unknown whether Honda has addressed this vulnerability in newer software updates or if manufacturers are aware of the issue.

Next Steps for Honda and Vehicle Owners

Automakers like Honda are likely to investigate this vulnerability and may issue security updates or patches to mitigate the risk. Vehicle owners should exercise caution when leaving their cars with valet services or in environments where USB access could be compromised. Security researchers may also expand testing to other Honda models and brands to assess the broader impact. In the near term, users are advised to restrict physical access to vehicle USB ports and monitor official recalls or updates for security patches.

Key Questions

Can this vulnerability be exploited remotely?

No, the attack requires physical access to the vehicle’s USB port to stage and install malicious updates.

Does Honda currently have a fix for this issue?

It is not yet confirmed whether Honda has issued a security patch or update to address this vulnerability. Ongoing investigations are expected.

Could this affect other car brands?

This specific vulnerability exploits Honda’s update signing process, but similar issues could exist in other vehicles with insecure update mechanisms. Further research is needed.

What should vehicle owners do now?

Owners should limit physical access to their vehicle’s USB ports, especially in public or insecure environments, until official security updates are available.

Source: Hacker News


You May Also Like

7 Best Office Product Scanners for Prime Day Deals in 2026

A Prime Day 2026 scanner report names seven office models to watch, but live deal prices and final discounts remain unconfirmed.

Struggling With Oculus 2? Simple Solutions To Get Your VR Gear Working Again

Effective solutions for common Oculus Quest 2 issues, based on user reports, to help users restore functionality quickly.

8BitDo launches the Arcade Controller Pro for hardcore fighting game fans

8BitDo launches the Arcade Controller Pro, a customizable, leverless controller designed for serious fighting game players, with new features including a display and hot-swappable switches.

Apple’s Siri AI push drives 12GB DRAM demand for Samsung and SK Hynix

Apple’s increased focus on Siri AI features has led to a surge in demand for 12GB DRAM modules from Samsung and SK Hynix, impacting the memory supply chain.