Skoda and Volkswagen Cars May Be Susceptible to Hacking Due to Infotainment System Vulnerabilities

Skoda Superb's infotainment system may allow malicious actors unrestricted code execution access.

Advertisement
Written by Shaurya Tomer, Edited by Siddharth Suvarna | Updated: 13 December 2024 15:51 IST
Highlights
  • Researchers discover vulnerabilities in the Skoda infotainment systems
  • It may allow remote code execution and vehicle location tracking
  • Skoda claims vulnerabilities have been addressed and eliminated

Skoda Superb III is reported to be one of the models impact by the vulnerabilities

Photo Credit: Skoda

Security researchers have discovered vulnerabilities of low-to-medium criticality in select Skoda and Volkswagen cars that may enable malicious actors to trigger certain controls, a cybersecurity firm announced at the Black Hat Europe 2024 event this week. At least 12 new vulnerabilities were found impacting the infotainment systems in the latest model of Skoda Superb III — a D-segment sedan manufactured by the Volkswagen Group which entered production in 2015. Although threat actors would need to connect to the vehicle via Bluetooth to get access, the attack may be carried even from a distance.

This builds upon the previous discovery of nine security flaws in the same vehicle that were reported last year.

Vulnerabilities in Skoda Cars

Cybersecurity firm PCAutomotive published a report detailing the vulnerabilities discovered in the third-generation model of Skoda Superb. The German sedan's MIB3 infotainment system may allow malicious actors unrestricted code execution access, enabling them to run malicious code upon startup. It is said to provide remote access to the vehicle's systems.

Advertisement

They may be able to track its speed and location in real time, eavesdrop on the in-car microphone, play sounds, and control its infotainment system. Another flaw may allow them exfiltrate the phone contact database if contact synchronisation with the phone is enabled. Further, the vulnerabilities could also allow access to the CAN bus which is used to connect with the vehicle's electronic control units (ECUs).

Although there are many suppliers of the MIB3 infotainment system, the researchers specifically talk about the one manufactured by Preh Car Connect Gmbh. It impacts the following models:

  1. Skoda Superb III
  2. Skoda Karoq
  3. Skoda Kodiaq
  4. VW Areteon
  5. VW Tiguan
  6. VW Passat
  7. VW T-Roc
  8. VW T-Cross
  9. VW Polo
  10. VW Golf

The sales data suggests that a total of 1.4 million vehicles from the Volkswagen Group are at risk. PCAutomotive reported the vulnerabilities to Skoda as part of its cybersecurity disclosure program. In a statement given to TechCrunch, Skoda revealed that they have been addressed and eliminated. “At no time was and is there any danger to the safety of our customers or our vehicles”, the German automotive company said.

 

Catch the latest from the Consumer Electronics Show on Gadgets 360, at our CES 2026 hub.

Advertisement

Related Stories

Popular Mobile Brands
  1. Here's How Much the Realme P4 Power Could Cost in India
  2. Infinix Note Edge Debuts With MediaTek Dimensity 7100 , 6,500mAh Battery
  3. Lava Blaze Duo 3 With a 1.6-Inch Rear Display Launched in India: See Price
  4. Samsung Galaxy S26 Ultra Colourways Spotted in Leaked SIM Tray Images
  5. Amazon Great Republic Day Sale: Top Laptop Deals Under Rs. 55,000
  6. Apple Could Bring LTPO+ Panel, Under-Display Face ID Tech to iPhone 18
  7. Sarvam Maya OTT Release: Know Everything About This Malayalam Fantasy Drama Film
  8. Top Deals on TWS During Amazon Great Republic Day Sale
  9. Arc Raiders Will Get Multiple New Maps This Year, Says Embark
  10. Vivo V70 FE Reportedly Spotted on Geekbench With This Chipset
  1. Champion OTT Release Date: When and Where to Watch This Telugu Movie Online?
  2. Tu Meri Main Tera Main Tera Tu Meri OTT Release Reportedly Revealed Online
  3. iPhone 18 Series to Feature LTPO+ Display Panel With Under-Display IR Sensor for Face ID: Report
  4. Infinix Note Edge Launched With 6,500mAh Battery, MediaTek Dimensity 7100 SoC
  5. Bitcoin Enters Consolidation Phase as Crypto Investors Turn Cautious
  6. Arc Raiders to Get Multiple New Maps in 2026, Embark Studios Confirms
  7. Preparation for the Next Life Now Streaming on Prime Video: Everything You Need to Know About American Drama Film
  8. Lava Blaze Duo 3 Launched in India With 1.6-Inch Rear Display, 5,000mAh Battery: Price, Specifications
  9. Vivo V70 FE Reportedly Surfaces on Geekbench With MediaTek Dimensity Chipset
  10. Salliyargal Now Available for Streaming Online: What You Need to Know About This Tamil Film
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.