Security Advisory Your car’s app could be telling Big Tech who you are and where you go

Security News
2 Replies 74 Views

Brownie2019

Level 23
Verified
Well-known
Forum Veteran
A study testing 21 cars from 19 brands and 30 companion apps found connections to advertising and tracking companies, and evidence that some apps shared sensitive personal data.

Modern cars can unlock remotely, route around traffic, stream entertainment, summon roadside help, and cool or heat the cabin before you get in. But those conveniences come with a privacy cost that drivers may struggle to see and are unable to refuse.

We’ve covered cars and privacy a few times before, especially after Mozilla researchers described cars as a “privacy nightmare.”

Texas Attorney General Ken Paxton investigated car manufacturers seeking details of their data collection and sharing practices, and sued General Motors over allegations that it sold customer driving data to third parties.

Researchers from Northeastern University, working with Consumer Reports, tested vehicles from model years 2022 through 2025 and companion apps, observing network traffic while cars were stationary, driven, and used through their apps. The results reinforce an uncomfortable reality: connected vehicles are data-collection platforms on wheels.

The results in a nutshell:
  • Both vehicles and companion apps contacted third-party domains, including those associated with advertising and tracking.
  • 19 of 21 vehicles contacted at least one third party over Wi-Fi.
  • 7 of 30 apps transmitted sensitive identifiers to third parties associated with advertising and tracking.
The troubling part is not that a car talks to its manufacturer. After all, a connected vehicle needs some network access for safety alerts, navigation, account functions, and maintenance. The bigger issue is the potential combination of identifiers. A vehicle identification number (VIN) can link a particular vehicle to its owner, while precise location can reveal highly sensitive patterns: where someone sleeps, works, worships, seeks medical care, spends time with friends, or travels. Add an email address or a name, and that information can be easier to connect to the detailed consumer profiles held by advertisers and data brokers.

And that’s before considering the privacy concerns around cameras that monitor drivers’ faces for signs of distraction or impairment.

Consent with strings attached​

Consent is a weak safeguard when drivers have to accept extensive terms to use functions advertised as part of the vehicle. Several manufacturers said their connected services were opt-in, but declining can mean losing useful functionality. For example, Consumer Reports noted a Tesla warning that refusing its agreement may result in:

“reduced functionality, serious damage, or inoperability.”
That hardly sounds like freely given, informed consent.

There was one sign that scrutiny can matter: after researchers presented their findings, Honda told Consumer Reports it had directed vendor Amplitude to delete location data it received and stopped sending it going forward. But consumers should not need an academic study to discover who their car or its app is sharing data with.

Especially when Amazon, Google, Meta, and Microsoft—companies that already know plenty about us—were among the leading recipients of the driver data.

Until automakers collect less data and provide clear privacy settings, meaningful opt-outs, and deletion controls, drivers should treat a connected car, and especially its companion app, as another privacy-sensitive device. Review app permissions, turn off optional data-sharing settings, avoid linking unnecessary accounts, and ask manufacturers what data they retain, share, and delete.
 
Hi Brownie2019, the most significant finding is not merely that cars contacted third-party domains. It is that seven of the 30 companion apps transmitted sensitive identifiers to advertising/tracking-associated companies, while five sent a VIN together with other personally identifiable information. A VIN is a durable link to a particular vehicle; combining it with an email address or precise location makes routine app telemetry considerably more revealing.

There is an important distinction in the methodology:

  • For vehicle Wi-Fi traffic, the researchers could identify network destinations, but encryption generally prevented them from seeing the payload. Therefore, 19 of 21 vehicles contacting a third party does not mean 19 vehicles were proved to be leaking personal data.
  • For the apps, the researchers installed a trusted certificate and used mitmproxy to inspect decrypted traffic. That provided the stronger evidence about VINs, email addresses, phone numbers and precise location.
  • During app testing they accepted every permission request and exercised all available functions. This demonstrates what the apps did in a fully permitted configuration, not necessarily what every owner experiences after denying optional permissions.

Those details, along with the October 2024–August 2025 testing period and model list, are set out in the researchers’ official project report. It is a substantial study, but still a US, model-specific snapshot rather than a verdict on every car from each brand.

Another necessary caution: contacting Amazon, Google or Microsoft infrastructure does not by itself prove that data was added to an advertising profile or sold. A connection might be cloud hosting, mapping, authentication or analytics. Observed transmission of identifiable data is evidence; a domain name alone is only a lead. Cloud services do have an uncanny habit of making everyone look guilty by association.

Practical steps for owners include:

  • Do not install or retain the companion app unless its remote functions are genuinely useful.
  • Restrict location to While Using the App, disable precise or background location where possible, and deny unrelated access such as contacts or calendars.
  • Review both the app/account privacy controls and the vehicle’s connected-services settings; insurance-driving programs and marketing analytics deserve particular scrutiny.
  • Avoid linking extra Google, Amazon or other accounts merely for convenience.
  • When selling, returning or renting a car, remove the vehicle from the app, unlink accounts, delete stored destinations and profiles, and reset the infotainment system.
  • Do not assume a DNS blocker solves this: the vehicle’s embedded cellular modem may bypass the phone and home network entirely.

The broader problem is the weak bargaining position. If declining data terms also disables remote climate control, navigation features or other advertised functions, “consent” becomes mostly paperwork with a button attached. The study’s strongest contribution is showing that this is measurable behaviour, not just alarming language buried in privacy policies.
 

Recently browsing

Members who viewed this thread in the last 5 minutes

You may also like...

Continue exploring the conversation.

Back
Top