BYD Australia is preparing a software update for the Shark 6 after a cybersecurity investigation identified an infotainment vulnerability exploited during a televised hacking demonstration.
BYD Australia has confirmed a software defect in the Shark 6 plug-in hybrid pickup after investigating cybersecurity vulnerabilities demonstrated during an episode of ABC’s Four Corners.
The investigation followed a demonstration by Canberra-based Fortify Labs, which showed how access to the Shark 6’s infotainment system could potentially expose vehicle data and functions. The demonstration included monitoring the vehicle’s location and accessing phone-call audio, while other tests showed control of features such as headlights and windscreen wipers.
According to BYD, its internal investigation successfully reproduced the infotainment access method. The automaker said researchers exploited a software defect that allowed Android Debug Bridge (ADB) functionality to be enabled before installing an untrusted third-party application.
The Shark 6 uses BYD’s DiLink infotainment platform, which is based on Android and is also used across other BYD and Denza vehicles. BYD said the vulnerability required special tools and initial physical access to the vehicle rather than allowing an attacker to gain entry remotely.
The company also explained that applications requesting sensitive permissions, including access to the microphone or vehicle location, required approval through the infotainment system.
BYD plans to address the vulnerability through an over-the-air software update. However, the update will only be released after undergoing extensive validation. The company is also assessing whether other models using related software could require similar corrective measures.
The automaker separately investigated access to the vehicle’s controller area network (CAN) bus. BYD said the demonstrated control of the headlights and windscreen wipers required direct physical access to the vehicle’s internal wiring and was therefore limited to the specific vehicle that had been accessed.
The company has launched a further risk assessment covering CAN message authenticity, integrity and verification. It also highlighted existing security measures around the OBD interface and cybersecurity safeguards aligned with UN R155 requirements.
Meanwhile, Fortify Labs said its demonstration was intended to highlight the risks associated with connected vehicles and manufacturer-level remote access. The cybersecurity firm has called for a consumer-facing cybersecurity star rating system covering connected-car security, including data collection and storage.
Fortify Labs also stressed that connected-vehicle cybersecurity is a global industry issue affecting manufacturers across different regions, rather than being limited to any particular country or automaker.