BYD confirms Shark 6 software flaw after TV hack, fix coming over the air
BYD says a software defect let a researcher install an app on a Shark 6 infotainment system, and an over-the-air update will fix it.
BYD has confirmed a software flaw in the Shark 6’s infotainment system that let a security researcher install an unauthorised app on the ute, and says it will fix it with an over-the-air update.
The flaw was exposed by an ABC Four Corners investigation broadcast in Australia on 21 September. In it, Dan Hreszczuk of Canberra-based Fortify Labs showed he could lock the doors, run the wipers and washers, switch the headlights, play content on the screen, record audio through the cabin microphone and track the vehicle’s location. The programme reported he could not reach systems such as the brakes and cameras, and that he had the Shark 6 for two weeks to develop the attack.

BYD Australia and New Zealand says its investigation, involving technical teams in Australia and China, found two separate ways in.
The first was through the infotainment system’s Android Debug Bridge, or ADB, a standard Android development tool that BYD says is switched off in production vehicles. BYD says the researcher used a software defect to turn ADB on and install a third-party app, and its engineers have been able to repeat both steps. It says that when the app asked for access to functions such as location or the microphone, a permission prompt appeared on the screen that had to be approved by hand.
The second route was the CAN bus, the network that carries messages between the vehicle’s systems. BYD says controlling the headlights and wipers this way meant tapping directly into the ute’s wiring.
“This method requires physical intervention on the target vehicle and is limited to the individual vehicle that has been physically accessed,” the company says.

BYD says any device trying to reach that network without cutting into the wiring would have to go through the OBD port, which uses device authentication and physical isolation and meets the UN R155 cybersecurity regulation.
The fix will close the path that allowed ADB to be switched on from the infotainment screen. BYD says it will be sent to Shark 6 owners in a future over-the-air update once it has been validated, and it is checking whether other models need the same update. A separate risk assessment will look at whether messages on the CAN bus need further protection.

There were 219 Shark 6 utes registered in New Zealand in September. BYD has previously said the personal data its connected vehicles send is limited to the VIN, email address and login details, and is held on servers in Australia.



Join the conversation