How the Jeep Cherokee hack worked: from the dashboard radio to the brakes
In the summer of 2015, a Jeep Cherokee cruising at 70 mph slowed to a crawl on a highway because 2 people who were not in the car told it to.[1] Nobody was hurt and it was a planned demonstration, but it led to a recall of about 1.4 million vehicles. This case file covers how the car was reached, what the recall cost, and the one design control that was missing.
What happened
Two security researchers spent years studying how modern cars could be attacked from a distance.[2] Their target was the Uconnect dashboard system that Fiat Chrysler fitted to many of its vehicles, the screen that handles the radio, navigation and phone features.[1]
In July 2015 they showed a reporter what they had found. With the reporter driving a 2014 Jeep Cherokee, they worked the car remotely and brought it down from 70 mph to a near stop. In the course of their research they showed they could also affect steering, braking, the wipers and washer fluid, the door locks and the dashboard gauges, and could shut off the engine.[1]
The published story drew wide attention. On July 24, 2015, Fiat Chrysler announced a recall of about 1.4 million vehicles, and federal safety regulators opened an inquiry into whether the fix went far enough.[1][3][4] The researchers then presented their work at the Black Hat security conference in Las Vegas in August 2015.[2]
How it worked
A modern car is a small network of computers. Some of them run the engine, brakes and steering and talk to each other over an internal network. Others run comfort and entertainment features. The safest design keeps those 2 worlds apart, so a problem in the entertainment side can never reach the driving side.
The Uconnect unit sat between those worlds. It had a cellular connection through a mobile carrier so it could offer connected features, which meant it could be reached from outside the car.[2] The researchers found that vulnerable vehicles could be found and contacted over that carrier's network, and estimated that more than a million cars might be exposed.[2]
The entertainment unit was not supposed to send commands to the rest of the car. But it could talk to a chip that did have access to the internal network, and the researchers found that the software on that chip could be replaced without proper authorization. Once that was done, messages from the dashboard system could reach the parts of the car that handle driving.[2] In plain terms, the wall between the radio and the brakes had a door, and the door was not locked.
What it cost
No one was harmed and no criminal attack using this flaw was reported. The price was paid by the manufacturer and its customers. The recall covered about 1.4 million vehicles across several brands, including 2013 to 2015 Ram pickups and Dodge Vipers, 2014 and 2015 Jeep Cherokee and Grand Cherokee and Dodge Durango SUVs, and 2015 Chrysler 200 and 300, Dodge Charger and Dodge Challenger models.[1]
Each affected owner needed a software update to the Uconnect system.[3][4] The National Highway Traffic Safety Administration opened an investigation to judge whether the recall was effective.[1] Beyond the direct cost, the case changed the conversation in the car industry: remote hacking was no longer a theory, and it could force a recall the same way a faulty part could.
The missing control
The missing control: isolating the infotainment system from the vehicle controls. The part of the car that talks to the outside world should have had no path to send commands to the engine, brakes or steering.
Every connected system will eventually have a bug. What turned this bug into a safety problem was that the internet-facing system could, with some work, give orders to the systems that move the car. Strict separation, backed by a check that only approved, signed software could run on the chip linking the 2 sides, would have limited any break-in to the radio and screen. Fixing that after the fact required a recall. Building it in from the start would have kept a dashboard flaw a dashboard problem.
What to do in your business
- Separate your guest and business networks. Put guest Wi-Fi, smart TVs, cameras and other gadgets on their own network, away from the computers that handle payments and customer records.
- Keep payment and control systems off the internet where you can. Card terminals, building controls and anything that moves money should only connect to what they strictly need.
- List every device that connects out. Printers, alarm panels, thermostats and vehicles with apps all count. You cannot protect what you do not know is connected.
- Apply updates and recalls promptly. When a vendor issues a security fix or recall for a product you own, schedule it the same week rather than waiting for the next service visit.
- Ask vendors how their products are separated. Before buying connected equipment, ask whether its online features can reach its critical functions and how updates are verified.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Guide: How a small business keeps software and devices patched, and why default passwords must go
- What caused the Equifax breach? An unpatched website and an expired certificate
- How the Capital One breach happened: one misconfigured cloud firewall
- What happened to Knight Capital: $460 million lost in 45 minutes
- How WannaCry hit the NHS: the fix existed 2 months before the attack
- How the Heartland breach happened: 130 million cards and an informant
- How the HSE cyber attack happened: one spreadsheet and 8 weeks of ignored alerts
- Every patching and monitoring control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.
- Dark Reading: Chrysler recalls 1.4 million vehicles after Jeep hacking demo
- Kaspersky Daily: Black Hat USA 2015, the full story of how that Jeep was hacked
- Stellantis North America: Unhacking the hack, ensuring security (July 24, 2015)
- Christian Science Monitor: Fiat Chrysler recalls 1.4 million Dodge, Jeep, Ram vehicles over hacking concerns