>From there the attacker can track the vehicle’s location, record audio from inside the car, and obtain the victim’s phonebook data.
Combined with:
>"In some cases pairing is possible without any user interaction"
You end up with a stalker's dream.
>In some cases pairing is possible without any user interaction.
Baloney. No implementations in the wild do this, or they would have loudly trumpeted it.
"In order to conduct an attack, the hacker needs to be in range and able to pair their laptop with the targeted infotainment system over Bluetooth. In some cases pairing is possible without any user interaction, while in others pairing requires user confirmation, or it may not be possible at all."
I agree that it's not world shatteringly bad, but... you're being a bit disingenuous. :)Or does there just need to be some communications link between the car's Bluetooth transceiver and the attacker?
I'd think that installing a BT <--> cell network bridge would easily solve that hurdle.
The cell -> phone -> bluetooth audio bridge?
I don't think there's an exploit there, but even assuming there was, it'd require an attacker to know the phone number of the person they are attacking and for the car to be on at the same time when they execute the attack.
Feels a little like the 90s ILUVYOU emails :)
I can see somebody setting up a Cassia in a car park and performing all sorts of bluetooth LE shenanigans remotely.