A smartphone app used to control vehicles across North America left users widely exposed to hackers, according to a Sophos publication. The MyCar app, from Canada-based AutoMobility Distribution, allowed anyone who knew about the vulnerability to control, monitor and access vehicles from an unauthorized device, the experts said.

MyCar is an application available on iOS and Android devices that allows users to install connected devices in their cars, turning them into IoT devices and controlling them via a mesh network connection. According to its website, the MyCar app enables users to control their cars remotely from anywhere by communicating with one of these devices through AutoMobility Distribution's servers.
Users can remotely start their car's engine, lock and unlock vehicles, or locate them. Other features include retrieving the temperature and battery levels of the vehicle and sharing your vehicle with other users, or even transferring it to a new owner.
The company sells the application based on a service plan. Users receive the smartphone application, the hardware device for installation in their car, and the service for a defined period of one or three years.
All of this sounds very convenient, especially when you want your nice car to be waiting for you warm on its cold mornings. Unfortunately, according to a vulnerability note issued by the Software Technology Institute of Carnegie Mellon University, the application allowed, at least until recently, hackers to take control of your car.
The developers of AutoMobility Distribution apparently wanted to create a way that would allow users to access functions in the car without worrying about usernames and passwords, so they made a serious mistake in the software development: they encoded the admin credentials directly into the application.
The vulnerability could lead to some serious consequences for users, according to the SEI CERT note, because an intruder could extract the credentials from the source code and use them to communicate with the server to put a user’s vehicle at risk:
A remote un-authenticated intruder may be able to send commands and retrieve data from a targeted MyCar unit. This could allow the intruder to learn the location of a target or gain unauthorized physical access to a vehicle.
The vulnerability was first reported by a cybersecurity researcher named JMaaxz, who made the following post on Twitter in late March:

Then, he posted the following tweet again when the vulnerability was disclosed:

The AutoMobility Distribution company told us it was updated on the issue in January, adding:
Since then, all the resources we have at our disposal have been used for the rapid handling of the situation and we have fully resolved the issue. During this period of vulnerability, no actual incident or issue involving a compromise of privacy or functionality has been reported to us or detected by our systems.
Fortunately, the risk has passed. SEI CERT explained that AutoMobility has updated its app to remove the credentials and has revoked admin credentials in older versions of the app. Other, redesigned versions of the app sold as Carlink, Linkr, Visions MyCar and MyCar Kia have also been patched, it added.
