I found all these details through examining the official firmware image and reverse engineering.
I don't remember if I reported Google Ads id to Google. It is interesting that Google doesn't notice and care about such use of their products.
You say "compromised". I say "monetised".
:sigh:
Germany, for example. Utterly bizarre and baffling that a democracy protects its politicians this way. /s
Moreover, no CVE is associated with this claimed vulnerability. It's not even stated which Android version or automotive head-unit variant version is affected.
Huh, how does that work anyway? And while we're at it, Apple CarPlay as well? Both can run wirelessly via Bluetooth, but BT is nowhere near capable enough to stream full bandwidth video?
Directions weren't coming from my phone's speaker or the car, but testing audio in the Maps app did (from the car).
Still not sure what combination of connections it had managed to get itself into!
Early version of Android Auto could transfer over USB 2.0 instead of Bluetooth, which works, but it's not near as high bandwidth.
This sentence doesn't make much sense - Auto (and CarPlay) still work in wired mode over USB 2.0 if the head unit supports it. They never worked over Bluetooth.
(And they use less than 15Mbps so USB 2.0s 480MBps are more than enough)
Remember that not that long ago viruses spread through floppy disks.
Today, people share USB sticks full of music from one car to another all the time. They also bring their music from their home car to a rental car and back.
It had the benefit of an information center with physical buttons too, so I could navigate around my library without touch screen madness or voice commands constantly failing to understand band and song names.
I've been doing it for years, since it's so much more convenient than the alternatives: plug the stick into my car and I have my whole music library there and it Just Works.
We use an USB key full of audio books: Harry Potter saga and The Quest of Ewilan among others. The whole family is hooked.
The car UI is much more reliable (no phone to unlock by the copilot, no Bluetooth disconnect). The phone battery is spared for navigation purposes.
Sure beats the radio, which plays 2 songs and then 5 min of commercials/sweepers, and has the gall to run ads on the HD text transmission on FM designed for song information.
Article does not say that.
Bottom line is that lots of HN commenters here, as is our wont, will see this as a platform bug with a hated rival and not a bad third party integration that introduced vulnerabilities.
Like, if it was a Linux-based edge system from some fly-by-night contractor, would you be OK with a headline like "Malware infects Debian based refrigerators"? What'd Debian do?
The two big things here in my mind are:
1. Android Automotive has gotten very popular since it provides so much and writing your own OS is very very hard and expensive as so many car makers found out
2. Aftermarket head units often use it (see #1) so it’s likely far easier to get out there than if you had to compromise Ford/VW/Volvo/whoever
The actually vulnerable system is a custom vehicle head unit that merely happens to be running a software stack based on AOSP. It's not even "Android" in a product marketing sense.
Again, it's like blaming Debian because some loon stuffed it in a wifi NAS or whatever and put a backdoor into their UI. It's insane.