Hackers Remotely Kill a Jeep on a Highway | WIRED
By WIRED
Key Concepts
- Remote car hacking
- Jeep Cherokee vulnerability
- Uconnect system
- Cellular network exploitation
- CAN bus (Controller Area Network)
- Security patch
- Black Hat hacker conference
- Automotive cybersecurity
Demonstration of Jeep Cherokee Hacking
Charlie Miller and Chris Valasek, two hackers, demonstrated the remote hacking of a 2014 Jeep Cherokee. The Jeep was completely stock, with no modifications or attached devices. The vulnerability stemmed from the Uconnect system, an internet-connected computer in the dashboard.
- Method: The hackers exploited a vulnerability in the Uconnect system, accessible via the car's cellular connection. This allowed them to send commands to the car's CAN bus, which controls various vehicle functions.
- Attacks Demonstrated:
- Turning on the fan and AC.
- Displaying a picture on the dashboard.
- Killing the engine while the car was in motion.
- Disabling the accelerator.
- Controlling the steering (at low speeds and in reverse).
- Messing with the speedometer.
- Disabling the brakes.
- Real-world Application: The demonstration highlighted the potential dangers of connected car technology and the need for robust cybersecurity measures.
Technical Details of the Exploit
The Uconnect system exposed a service that allowed the hackers to query information (like GPS data) and run commands.
- Lateral Movement: After gaining initial access via the cellular network, the hackers moved laterally within the car's systems to send "canned messages" to the CAN bus. These messages controlled functions like steering, windshield wipers, and braking.
- Vulnerable Vehicles: The hackers stated that hundreds of thousands of late-model Chrysler vehicles with the Uconnect system may be vulnerable.
Response and Mitigation
- Disclosure: Charlie and Chris planned to release a portion of their exploit code at the Black Hat hacker conference.
- Chrysler's Response: Chrysler was issuing a security patch to address the vulnerability.
- Call for Action: The hackers emphasized the need for more research and attention to automotive cybersecurity, as connected cars become increasingly common.
Ethical Considerations and Safety
- Controlled Experiment: The hackers emphasized that the demonstration was a controlled experiment designed to highlight the vulnerability in a safe manner.
- "We did it in a safe way as we could so we didn't want you get hurt obviously." - Charlie Miller
- Motivation: Their goal was to identify vulnerabilities and get them fixed, not to cause harm.
- Limited Scope: They acknowledged that they could not analyze every car model and hoped their research would encourage others to focus on the problem.
- "We're only two guys with one car right so you know we can't look at every car and we want to release this information because more people like us need to be focused on this problem." - Chris Valasek
Conclusion
The demonstration of the Jeep Cherokee hack served as a stark warning about the cybersecurity risks associated with connected cars. The vulnerability in the Uconnect system allowed hackers to remotely control critical vehicle functions, highlighting the need for robust security measures and ongoing research in the automotive industry. The hackers' disclosure of the vulnerability and Chrysler's subsequent security patch aimed to mitigate the immediate risk, but the incident underscored the broader challenge of securing an increasingly connected automotive landscape.
Chat with this Video
AI-PoweredLoad the transcript when you're ready to chat so the initial page stays lighter.
Related Videos

Is there a Chinese cyber threat to EU solar energy? | DW News
DW News

i f**k'd up
Meet Kevin

3 AI Stocks Insiders Are Selling. Most Aren't Ready for What Happens Next.
MarketBeat

From Know Your Customer to Know Your Reality in the Age of AI | Mr. Smarak Swain | TEDxKPRCAS
TEDx Talks

OpenAI's New GPT Cyber Beats Mythos 5
AI Revolution

Top Stocks I'm Buying For Huge Growth In July 2026
Ticker Symbol: YOU

Michael Saylor's Bitcoin buying machine just sputtered
Yahoo Finance