• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Exclusive

An hour in the Oval Office with President Trump Fortune Editor-in-Chief: Alyson Shontell sat down with President Trump in the Oval Office for an hour. Tariffs, Intel, AI, Boeing, Iran—and the question every CEO eventually has to answer: who's next?

An hour in the Oval Office with President Trump Fortune Editor-in-Chief: Alyson Shontell sat down with President Trump in the Oval Office for an hour. Tariffs, Intel, AI, Boeing, Iran—and the question every CEO eventually has to answer: who's next?

An hour in the Oval Office with President Trump Fortune Editor-in-Chief: Alyson Shontell sat down with President Trump in the Oval Office for an hour. Tariffs, Intel, AI, Boeing, Iran—and the question every CEO eventually has to answer: who's next?

An hour in the Oval Office with President Trump Fortune Editor-in-Chief: Alyson Shontell sat down with President Trump in the Oval Office for an hour. Tariffs, Intel, AI, Boeing, Iran—and the question every CEO eventually has to answer: who's next?

An hour in the Oval Office with President Trump Fortune Editor-in-Chief: Alyson Shontell sat down with President Trump in the Oval Office for an hour. Tariffs, Intel, AI, Boeing, Iran—and the question every CEO eventually has to answer: who's next?

An hour in the Oval Office with President Trump Fortune Editor-in-Chief: Alyson Shontell sat down with President Trump in the Oval Office for an hour. Tariffs, Intel, AI, Boeing, Iran—and the question every CEO eventually has to answer: who's next?

An hour in the Oval Office with President Trump Fortune Editor-in-Chief: Alyson Shontell sat down with President Trump in the Oval Office for an hour. Tariffs, Intel, AI, Boeing, Iran—and the question every CEO eventually has to answer: who's next?

An hour in the Oval Office with President Trump Fortune Editor-in-Chief: Alyson Shontell sat down with President Trump in the Oval Office for an hour. Tariffs, Intel, AI, Boeing, Iran—and the question every CEO eventually has to answer: who's next?

An hour in the Oval Office with President Trump Fortune Editor-in-Chief: Alyson Shontell sat down with President Trump in the Oval Office for an hour. Tariffs, Intel, AI, Boeing, Iran—and the question every CEO eventually has to answer: who's next?

An hour in the Oval Office with President Trump Fortune Editor-in-Chief: Alyson Shontell sat down with President Trump in the Oval Office for an hour. Tariffs, Intel, AI, Boeing, Iran—and the question every CEO eventually has to answer: who's next?

TechGlobal 500

White hat hacker: GM’s OnStar app is still vulnerable

By
Kirsten Korosec
Kirsten Korosec
Down Arrow Button Icon
By
Kirsten Korosec
Kirsten Korosec
Down Arrow Button Icon
July 31, 2015, 9:00 AM ET
General Motors

The world of connected cars is supposed to be a safer place—an environment where sensors and software help drivers navigate the roads more safely. However, that connectedness is also exposing drivers, and automakers, to a new set of risks: hackers.

Just one week after experts demonstrated how they could remotely take over the controls of a Jeep Cherokee, a white hat hacker (the term used to describe those people who hack with benevolence) has uncovered a security flaw with the mobile app for General Motors’ OnStar vehicle communications system.

This time, the problem isn’t with the vehicles, but with the mobile software.

Hacker Samy Kamkar posted a video on YouTube on Thursday describing how a device that he built can intercept communications between the OnStar RemoteLink mobile app and the OnStar service, Wired reported. Using the device—that he calls OwnStar—Kamkar showed how he was able to locate, unlock, and remote-start vehicles. The device can give the attacker the car’s location, make, and model, as well as power to unlock and remote-start the car.

[youtube https://www.youtube.com/watch?v=3olXUbS-prU]

GM’s RemoteLink app started as a feature for Chevrolet Volt owners to remotely check the status of their vehicle’s battery life, according to the company. The idea expanded and connected with OnStar to give drivers up-to-date vehicle information such as oil level, tire pressure, fuel level, and lifetime miles per gallon. Today, the app has been installed on at least 1 million Android devices, according to Google Play Store.

GM’s RemoteLink smartphone app not only lets user unlock and remote-start their cars, it displays a summary of the diagnostic data GM collects. Drivers can track fuel economy or when service is needed. So, while this latest attack might not be as dangerous as someone taking over your car, it does show one more way a hacker can gain access to personal data. The OwnStar hacking device lets the attacks do just about anything—horns, lights, unlocking, and starting—to the car except put it in gear and drive away.

Kamkar says he’ll reveal more details about the OnStar security flaw, as well as other car-related attacks in future videos and at DefCon, an annual security conference to be held in Las Vegas next week.

 

GM’s product cybersecurity representatives have reviewed the recently identified potential vulnerability, spokeswoman Renee Rashid-Merem told Fortune, adding that the company hasn’t had any other reports of hacking the RemoteLink app aside from the demonstration by Kamkar.

GM (GM) worked with the researcher to secure its back-office system and reduce risk, according to Rashid-Merem. Kamkar says while GM and OnStar have been receptive, a vulnerability still exists. Kamkar recommends consumers not open the app until an update has been issued.

“The systems work is done, which was a major step to ensure security for customers,” Rashid-Merem said in an email. “To fully mitigate the issue, we are also doing a RemoteLink app update which will be available in app stores soon.”

GM is hardly a newcomer to connected cars. The company has offered some version of wireless connectivity in its vehicles since 1996, when OnStar was born. The company has also put Wi-Fi into dozens of new Buick, Chevrolet, Cadillac, and GMC models, thanks to an AT&T 4G radio module that gives users a high-speed link comparable to what you might experience on the latest Samsung Galaxy or 4G iPad.

The company even has a cybersecurity chief who is in charge of efforts to protect the computers that run GM cars. And yet, even with considerable experience and security measures, a vulnerability was exposed.

[fortune-brightcove videoid=3921692114001]

 

This latest incident shows how mobile apps are just another gateway into a vehicle.

It also reveals the significant hurdles that lay ahead for automakers. The recent formation of the Alliance of Automobile Manufacturers (AAM)—an alliance of 12 automakers including Ford (F), General Motors , and Mercedes-Benz—couldn’t have come any sooner.

The alliance is creating an information sharing and analysis center (ISAC) that’s expected to be up and running later this year. The Center will help participating companies keep each other aware of the latest hacking threats targeting vehicles.

Sign up for Data Sheet, Fortune’s daily morning newsletter about the business of technology.

About the Author
By Kirsten Korosec
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

Google’s I/O conference showed how the company is being completely rebuilt for AI—for better or for worse
Big TechGoogle
Google’s I/O conference showed how the company is being completely rebuilt for AI—for better or for worse
By Alexei Oreskovic and Sharon GoldmanMay 19, 2026
32 minutes ago
Bolt CEO Ryan Breslow
Workplace CultureFortune Workplace Innovation
Bolt CEO says he let go of his entire HR team for creating problems that didn’t exist: ‘Those problems disappeared when I let them go’: 
By Preston ForeMay 19, 2026
2 hours ago
Svenja Gudell, Chief Economist, Indeed
SuccessFortune Workplace Innovation
Indeed chief economist says the sectors most exposed to AI are seeing a big growth in job demand
By Emma BurleighMay 19, 2026
2 hours ago
A Pizza Hut workers prepares an order for delivery.
LawFood and drink
Pizza Hut franchisee claims $100 million losses from ‘cascading operational breakdowns’ in AI adoption gone wrong
By Sasha RogelbergMay 19, 2026
3 hours ago
Santora gestures towards himself
Future of WorkGen Z
WeWork and Upwork CEOs confirm the Gen Z hiring nightmare is real—but it’s nothing new
By Jacqueline MunisMay 19, 2026
4 hours ago
U.S. President Donald Trump speaking at a podium flanked by signs that say "Winning the AI Race."
NewslettersEye on AI
The times they are a-changin’: Washington suddenly warms to regulating AI
By Jeremy KahnMay 19, 2026
4 hours ago

Most Popular

While Trump insisted the Iran war would end ‘soon,’ an account in his name was buying millions in oil, defense, and gold
Economy
While Trump insisted the Iran war would end ‘soon,’ an account in his name was buying millions in oil, defense, and gold
By Eva RoytburgMay 18, 2026
1 day ago
The Bezos family just donated $100 million to help achieve one of Mayor Zohran Mamdani’s top campaign promises
Politics
The Bezos family just donated $100 million to help achieve one of Mayor Zohran Mamdani’s top campaign promises
By Jake AngeloMay 12, 2026
7 days ago
Current price of oil as of May 18, 2026
Personal Finance
Current price of oil as of May 18, 2026
By Joseph HostetlerMay 18, 2026
1 day ago
EXCLUSIVE: An hour in the Oval Office with the CEO-in-Chief, President Trump
Politics
EXCLUSIVE: An hour in the Oval Office with the CEO-in-Chief, President Trump
By Alyson ShontellMay 18, 2026
2 days ago
Current price of silver as of Monday, May 18, 2026
Personal Finance
Current price of silver as of Monday, May 18, 2026
By Joseph HostetlerMay 18, 2026
1 day ago
Spirit Airlines apologizes to all the Americans who can't afford any summer vacation flights as it shuts down
Travel & Leisure
Spirit Airlines apologizes to all the Americans who can't afford any summer vacation flights as it shuts down
By Rio Yamat and The Associated PressMay 18, 2026
1 day ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.