BYD has provided additional details about cybersecurity testing shown in an Australian documentary involving its Shark 6 plug-in hybrid pickup, saying the vehicle’s infotainment system was accessed through Android Debug Bridge (ADB) and an untrusted third-party application.
The issue came to light in an episode of ABC’s Four Corners. Cybersecurity specialist Dan Hreszczuk was given a Shark 6 for two weeks and demonstrated access to the vehicle’s interior microphones, door locks and audio system. The program did not disclose the specific method used to access the truck.
Infotainment access involved ADB
According to BYD, Hreszczuk used a specialized tool to breach the infotainment system’s ADB pathway and install an application from an untrusted third party. BYD said it was able to reproduce the vulnerability during its own testing.
However, the automaker said accessing location information and the vehicle’s microphones also required the driver to approve a permission request displayed on the infotainment screen. That requirement was not disclosed in the documentary, according to BYD.
ADB is ordinarily disabled in the vehicle. BYD said it is developing an over-the-air software update that will remove the pathway used to enable it. The company has not announced when the update will be ready, but said other models would also receive new software if comparable vulnerabilities are identified.
Headlights and wipers required physical access
The documentary also showed the Shark 6’s windshield wipers being activated and its headlights switched off while the pickup was being driven at night. BYD said those functions were not controlled solely through the infotainment vulnerability.
Instead, the automaker said the hacker accessed the vehicle’s internal wiring and connected to its controller area network, or CAN bus. Hreszczuk later confirmed in a blog post that he had spliced into the Shark 6’s wiring and installed a low-cost Raspberry Pi computer.
That method requires physical access to the vehicle rather than a remote attacker operating only from a computer. The source material says the same type of approach could potentially be replicated on other modern vehicles, but does not identify a specific model or vulnerability beyond the Shark 6 demonstration.
Additional OBD protections
BYD also said it has introduced additional security measures for the Shark 6’s onboard diagnostics interface. The updated approach requires physical isolation and device authentication, measures intended to reduce the possibility of using an OBD device to reach critical vehicle functions.
The response addresses two separate elements of the documentary’s demonstration: software access through the infotainment system and direct physical access to the vehicle’s wiring. BYD’s planned over-the-air update is aimed at the ADB vulnerability, while the OBD changes are intended to limit access through the diagnostic interface.



0 Comments