CarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Notification
  • Autonomous Driving
  • Automotive Ethernet
  • BMS
  • ECU
  • EV
  • ISO/SAE 21434
  • Infotainment
  • OTA Updates
  • OBD-II
  • Pwn2Own
  • RCE
  • SDVs
  • TCU
  • UNECE R155
Cybersecurity

St. Paul pulls plate reader cameras after data reached immigration agents

Policy & Compliance

China freezes vehicle software to end patch-later OTA era

Policy & Compliance

NRMA and Lexus Australia push Canberra toward car data law

Policy & Compliance

Quebec report declares car data consent fundamentally broken

Font ResizerAa
CarThreatCarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
Search
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Sign In Sign In
Follow US
© 2026 Carthreat.com. All right reserved.
Cybersecurity

Rollback bug lets attackers clone key fobs in rolling code systems

A rollback flaw paired with brute force lets attackers clone key fobs from aftermarket rolling code systems, research with three CVEs will show at DEF CON 34.

CarThreat Staff
Last updated: August 6, 2026 8:54 pm
By
ctadmin
2 Min Read
SHARE

Researchers will show at DEF CON 34 how a popular aftermarket rolling code system can be cracked to clone key fobs, a finding that earned three CVEs this year.

A widely sold aftermarket security system built its reputation on blocking fob cloning and unauthorized access, researcher Danilo Erazo explains. Erazo reversed the protocol to map its frame structure and cryptographic design, surfacing weaknesses that had never been documented.

The attack methodology couples a rollback flaw with a practical brute force of the rolling code stream. Valid codes fall out of the process, giving attackers everything they need to duplicate a real fob and operate the target vehicle. The year 2026 has already seen three CVE identifiers attached to the research, and the affected hardware is spread across numerous countries.

The presentation, “Unlocking Vehicles by Brute-Forcing Rolling Code Systems,” runs Sunday morning at the Car Hacking Village’s Creator Stage.

Rolling codes are supposed to defeat replay attacks by changing the transmitted code on every press. The research is a reminder that assumptions about rolling code security can fail in practice: cryptographic weaknesses and rollback behavior can turn a decades-old protection mechanism into a gate that opens for attackers.

For owners of vehicles using aftermarket security products, the findings reinforce the value of checking whether a system’s flaws are patched and whether vendors respond to coordinated disclosure.

Join Our Newsletter
Subscribe to our newsletter to get our newest articles instantly!
TAGGED:CybersecurityDEF CON 34Digital KeysKeyless EntryVehicle TheftVulnerabilities
SOURCES:Car Hacking Village
Share This Article
Facebook Email Copy Link

Follow US

Find US on Social Medias
FacebookLike
XFollow
YoutubeSubscribe

You Might Also Like

Policy & Compliance

China freezes vehicle software to end patch-later OTA era

By
ctadmin
August 27, 2026
Cybersecurity

Belgium becomes first in Europe to say yes to driverless cars on public highways

By
ctadmin
July 12, 2026
Cybersecurity

WeRide and Uber Target Zurich for Robotaxi Launch with Driverless Permit

By
ctadmin
June 19, 2026
Cybersecurity

Believ and UrbanChain Deliver Verified Local Renewable Power to EV Chargers

By
ctadmin
June 17, 2026
Autonomous & AI SystemsCar NewsCybersecurityPolicy & Compliance

Zoox recalls robotaxis after smoke-blind software fails at fire scene

By
ctadmin
July 18, 2026
Cybersecurity

GlobalLogic and PlaxidityX Partner to Embed DevSecOps Into SDV Cloud Development

By
ctadmin
May 22, 2026

CarThreat

Intelligence for the EV and automotive security market
  • News
  • Features
  • Spotlight
  • Events
  • About Carthreat
  • Our Mission
  • Services
  • Contact Us
  • OBD-II
  • Automotive Ethernet
  • TCU
  • Infotainment Systems
  • SDVs
  • BMS
  • ECU Security
  • CAN Bus
  • OTA Updates
  • Vulnerabilities
  • Relay Attacks
  • RCE
  • Threat Intelligence
  • Cybersecurity
  • Digital Keys
  • Bluetooth Security
  • ISO/SAE 21434
  • UNECE R155
  • Regulations
  • Data Privacy
  • EVs
  • Autonomous Driving
  • Pwn2Own Automotive

© 2026 Carthreat.com. All right reserved.  Privacy Policy | Legal

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?