HeadlinesBriefing favicon HeadlinesBriefing.com

Honda Civic Headunit Vulnerability Exposed via AOSP Test Key

Hacker News •
×

Honda’s 2021 Civic headunit accepts USB‑based updates signed with the publicly‑known AOSP test key, allowing attackers with physical access to flash arbitrary code.

The flaw stems from Honda’s update path using stock AOSP verification logic while embedding the test key in res/keys. An attacker can craft a signed image with ota-builder, install a setuid su binary, and gain root on the infotainment system.

This discovery, dubbed “EvilValet,” shows that any Civic owner who leaves the car at a valet can unknowingly expose their headunit to malicious software. The vulnerability highlights insufficient key management in automotive OTA processes and urges manufacturers to enforce stricter signing practices.