I am looking for owners of recent Volvo and Polestar models, seeking help to better characterize a security vulnerability that I found while digging into the software stack of my own car, a Volvo EX30. Before I make the responsible disclosure to Volvo Cars, I'd like to confirm whether it affects other models as well.
This is where I need some help: I need access to the software running on the AAOS (Android Automotive OS) infotainment systems of potentially affected models. Of course only the system part of the head unit, nothing that is individual to a vehicle (device/vehicle ID, user generated data, etc.).
The particular brands/models I'm interested in:
- all Volvo Cars models that use AAOS ins their infotainment system (vehicles made in the last 3-5 years or even older models that might have gotten it as an upgrade)
- all Polestar models that use AAOS in their infotainment system (vehicles made in the last 5-6 years)
I suspect that the issue predates the arrival of AAOS, but I'm not really familiar with the Sensus architecture. Still, if somebody has a file system dump from an older Sensus infotainment system, I'd like to take a look at it too.
Here's what I need:
- a dump of parts of the file system like
/product, /system, /system_ext, /vendor, etc. (or an OTA update package, i.e. *.VBF files)
- name of the vehicle model
- model year
- software version
I also wrote a non-instrusive app that can extract a file system dump from an AAOS device (of course not everything, just what any 3rd party app can read), it's available on GitHub. You can compile it yourself or I can give access to my Google Play Internal Testing track.
I'll not give away any details about the vulnerability itself before I gave Volvo a chance to fix it, so don't even ask.
If somebody is willing to help with this, I wrote a more lengthy page about the system dumper app, my motivation, myself (I don't try to hide my identity) and how you can contact me.
Of course I understand that anybody could write this with malicious intent in mind. I don't think there's much more I could do to convince people that my intentions are honest. If I don't get useful feedback/help, I'll just hand in (to Volvo Cars) what I know about the EX30 and hope they'll actually fix it. The worst that could happen is that they do an ineffective fix for the EX30, they don't fix any other models (claiming that they are not affected by the issue and I cannot prove them wrong) and in reality they all remain vulnerable and somebody with malicious intent starts working on this. In that scenario there's still the option to involve regional authorities (US, EU, etc.) and the media. Both can exercise the necessary pressure to make an actual fix happen (there has been precedent with models from other automakers).