DigiNews

Tech Watch by Johan Denoyer

← Back to articles

10th Gen Honda Civic Updates Are Signed with AOSP Test Keys

Quality: 7/10 Relevance: 9/10

Summary

The piece reports a vulnerability in 10th-gen Honda Civic headunits where the AOSP test key remains in the update path, allowing arbitrary code execution via USB with physical access. It coins the attack 'EvilValet', describes supporting tooling (ota-builder, apk-rebuilder), and calls for contributors while noting the need for careful handling of updates and potential mitigations.

🚀 Service construit par Johan Denoyer