The trend of revelations regarding car hacking continues with three researchers from CrySys Lab and the University of Technology and Economics of Budapest saying they were able to silently disable the airbag system in an Audi TT model.
Presenting their findings to The Register, the three explained that while their attack is not as significant as all the recent car hacking cases over the past six months, theirs is more likely to happen in real life.
This is because it is based on a zero-day exploit found in automotive engineering software used to debug and fix cars sold by the Volkswagen Group. This software is sold by third parties, not by Volkswagen itself.
The researchers said they only experimented with this exploit on an Audi TT model, but other car makes and models could also be vulnerable, at least in theory.
The attack, as described by the three scientists, is based on infecting the computers of a car dealership with malware that exploits this vulnerability in the computerized troubleshooting tools used by the car mechanics
When this tool is connected to an Audi TT to perform a routine check for maintenance or repair, the malware will disable the car's airbag system, all without the mechanic or car owner knowing.
Even Buttyán, one of the three researchers, notes that the risk is greater for this attack because previous car vulnerabilities relied on weak points in the car's software, while their attack exploits security gaps in ordinary computers, which we all know can be quite deficient.
This is the exact scenario that security researcher Craig Smith warned about earlier this month during his presentation at DerbyCon, where he outlined a method that attacks cars using cars that are at car dealerships and repair shops.

