Vulnerabilities have been identified in infotainment units of some Skoda cars , which could allow hackers to gain remote access to controls and track the vehicles' location in real time.

PCAutomotive, a leading cybersecurity firm specializing in the automotive sector, revealed the existence of 12 new vulnerabilities affecting the latest Skoda Superb III sedan model during this week’s Black Hat Europe conference. The revelation comes a year after nine other vulnerabilities were reported in the same model.
Read more: Millions of Kia cars vulnerable to hack due to vulnerability
Skoda, a brand of German automaker Volkswagen, appears to be facing serious security issues in its systems.
Danila Parnishchev, head of security assessment at PCAutomotive, told TechCrunch that these vulnerabilities could be combined and exploited by hackers to inject malware into the vehicle. According to Parnishchev, an attacker could exploit the vulnerabilities by connecting to the Skoda Superb III’s multimedia unit via Bluetooth, provided that it is within 10 meters. “The attack does not require authentication,” he noted.
The vulnerabilities were found in the vehicle's MIB3 infotainment module and could allow attackers to execute arbitrary code and install malware whenever the module is powered on. This could allow hackers to access the vehicle's live GPS coordinates and speed data, record conversations through the microphone, take screenshots of the infotainment module, or even produce unwanted sounds inside the car, according to PCAutomotive.
See also: Hyundai Mobis obtains cybersecurity certification in Europe
Parnishchev told TechCrunch that the vulnerabilities PCAutomotive identified and verified in the Superb III allow an attacker to extract the owner's phone's contact database, provided they have enabled contact syncing with their vehicle.
“Usually, phones are encrypted, which makes it difficult to extract the contact database,” Parnishchev said. “However, in the entertainment unit, this can be easily done, as the database is stored in plain text.”
Parnishchev emphasized that no way was found to bypass the vehicle's network restrictions to gain access to critical safety systems, such as the steering wheel, brakes, and throttle.
In its report, shared with TechCrunch ahead of its publication on Thursday, PCAutomotive noted that the vulnerable MIB3 modules are used in many Volkswagen and Skoda models. Based on public sales data, it estimates that there may be more than 1.4 million vulnerable vehicles.
Read also: APT29 hackers lure diplomats with car ads – Greek diplomats also at risk
At the same time, Parnishchev noted that this number could be even higher if the second-hand parts market is taken into account. “If you search for a part number on eBay, you are very likely to find it. And if the previous user has not deleted their data, their contact database will remain there,” he explained.

PCAutomotive said Volkswagen fixed the vulnerabilities after they were reported through the company's security issue reporting program.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
In a written statement to TechCrunch, Skoda spokesperson Tom Drechsler said: “The vulnerabilities identified in the infotainment system have been addressed and continue to be resolved through continuous improvement management throughout our product lifecycle. At no time has there been, nor is there, a risk to the safety of our customers or our vehicles.”
See more: Hyundai and Kia release patch for dangerous security flaw
Source: techcrunch
