Automotive
Authentication & Access Bypass
Wireless Key Stroke Injection on vehicle Infotainment
Successful exploitation allows an attacker within Bluetooth range to inject unauthorized keystrokes into the infotainment system.
.png)
Overview
A vulnerability was identified in the Bluetooth Human Interface Device (HID) handling mechanism of the infotainment system running Android v12.0. The BLE stack and input processing components accept peripheral devices with insufficient verification, allowing a spoofed HID device to be recognized as a legitimate input source. As a result, the system may process unsolicited keystroke inputs originating from external, non-trusted wireless devices. This behavior exposes the infotainment unit to unauthorized interaction through its BLE Interface.
Vulnerability details
A vulnerability was identified in the Bluetooth Human Interface Device (HID) handling mechanism of the infotainment system running Android v12.0.
What an attacker can do
Successful exploitation allows an attacker within Bluetooth range to inject unauthorized keystrokes into the infotainment system. This can lead to unintended menu navigation, application launches, setting modifications, and interaction with system features without user consent. Although it does not directly affect other vehicle ECUs, it poses a significant risk by enabling remote manipulation of infotainment functions.
Disclosure timeline
2025-09-23 Reported to Vendor
2025-11-20 CVE ID Reserved
2025-12-05 CVE published
References
Credits
Shubham S. Thorat – Payatu Security Consulting Pvt. Ltd.
















