Security researchers have identified multiple vulnerabilities in Volkswagen Group’s connected car systems and applications that could potentially expose sensitive user data and vehicle information. The findings, revealed in 2025, encompass both infotainment system flaws and connected car app security issues, contributing to growing concerns about automotive cybersecurity in an increasingly connected vehicle landscape.
Researchers discovered vulnerabilities in Volkswagen Group vehicle infotainment systems that could enable unauthorized access to real-time vehicle tracking, GPS data, speed monitoring, in-car audio recording, and infotainment screenshot capture. A notable vulnerability involved the handling of contact photos, which could trigger a buffer overflow condition. The findings reflect broader industry trends focusing on securing vehicle connectivity systems, as demonstrated by organizations like the Car Connectivity Consortium which develops security standards for connected vehicles.
In response to these findings, a Skoda spokesperson stated, “The reported vulnerabilities in the infotainment system have been and are being addressed and eliminated through continuous improvement management via the lifecycle of our products. At no time was and is there any danger to the safety of our customers or our vehicles.”
Separately, cybersecurity researcher Vishal Bhaskar identified significant vulnerabilities in Volkswagen’s connected car app after purchasing a pre-owned vehicle in 2024. Bhaskar discovered that the app lacked proper security controls for one-time password (OTP) verification, allowing potential brute-force attacks on the 4-digit OTP system. The finding raises particular concern given the automotive industry’s increasing adoption of mobile authentication systems and digital vehicle access solutions.
The investigation revealed three critical security flaws: exposed internal credentials through an API endpoint, including plaintext passwords and third-party service tokens; absence of lockout mechanisms for failed authentication attempts; and potential security gaps in user authentication and vehicle data handling. The vulnerabilities highlight the importance of robust IoT security measures in automotive applications.
The discoveries come at a time when automotive manufacturers are rapidly expanding their connected car capabilities and digital services, with industry analysts predicting significant growth in the automotive cybersecurity market over the coming years. The security challenges underscore the need for stronger authentication protocols and comprehensive security testing in connected vehicle systems.
Sources: Security Affairs, Cybersecurity News, Techlomedia, Technadu