Skip to main content

OnStar hack can remotely unlock cars and start engines, GM claims to have a fix

gm maps for self driving cars onstar
Following a dramatic demonstration of car hacking involving a Jeep Cherokee, a researcher claims to have found a way to break into General Motors’ OnStar telematics system and take control of certain vehicle functions remotely. GM says it has a fix, though.

Sammy Kamkar built a small device about the size of a router that he calls, a bit cheekily, “OwnStar.” It’s designed to break into the OnStar system and do anything one of its operators can do, including remotely track a car, lock or unlock doors, or start the engine, according to Wired.

Recommended Videos

Kamkar reported the issue to GM before the Wired story was published, and plans to reveal full details of the hack during the DefCon conference next week. The carmaker claims to have already fixed the problem by instituting stronger certificate controls at the servers that control the OnStar RemoteLink remote-access app.

OwnStar relies on this smartphone app, which sends signals to a car’s onboard computers. The device must be positioned somewhere on the car itself, close enough to intercept these signals. It then poses as the car’s actual systems, and harvests the car owner’s credentials. A hacker can use those credentials to mimic the app, and give remote commands to the car.

This was possible because the OnStar app wasn’t originally programmed to check for fake encryption certificates, something GM claims to have corrected in its recent update. Unlike with the Chrysler vulnerability exposed by researchers Chris Valasek and Charlie Miller, this was done through the OnStar system’s servers, so owners won’t have to take any action.

However, Kamkar isn’t convinced that the problem has been fixed. Yesterday, he tweeted that the issue is “not actually resolved yet.” He said he had spoken to GM, and was told the company was working on a final fix.

Earlier this week, GM announced that it had surpassed 1 billion OnStar customer interactions, including those using the app, phone calls, and in-vehicle interfaces. It says about 8.8 million of those interactions were done through the app, and claims to have over 7 million OnStar subscribers right now.

Stephen Edelstein
Stephen is a freelance automotive journalist covering all things cars. He likes anything with four wheels, from classic cars…
These new NASA EVs will drive astronauts part way to the moon (sort of)
NASA's new crew transportation electric vehicles.

Three specially designed, fully electric, environmentally friendly crew transportation vehicles for Artemis missions arrived at NASA’s Kennedy Space Center in Florida this week. The zero-emission vehicles, which will carry astronauts to Launch Complex 39B for Artemis missions, were delivered by Canoo Technologies of Torrance, California. NASA/Isaac Watson

NASA has shown off a trio of new all-electric vehicles that will shuttle the next generation of lunar astronauts to the launchpad at the Kennedy Space Center.

Read more
5 upcoming EVs I’m excited for, from luxury SUVs to budget champions
Lotus Eletre

Almost every major automaker has released an EV by now -- or plans to soon -- and makers like Ford and Kia already have a variety to choose from. But if you haven't found one that's right for you yet, hang tight. There are dozens of announced electric car models that have yet to come out, and it's clear that the future of EVs is bright.

From longer range to lower prices, the next batch of EVs gives us plenty to get excited about. Here are five upcoming EVs that we can't wait to drive.
Volvo EX30

Read more
Tesla shows off first Cybertruck after two years of delays
The first Cybertruck built at Tesla's Giga Texas facility.

The first Cybertruck built at Tesla's Giga Texas facility. Tesla

Tesla has shown off the first Cybertruck to roll off the production line at its new Gigafactory plant in Austin, Texas.

Read more