The phone you connected to your old car may still be talking to it, long after the car belongs to someone else. Researchers at the University of Memphis found that used infotainment stereos keep the Bluetooth credentials of every handset ever paired with them, together with personal records from the previous owner.
Their demonstration started with a wrecked 2016 Honda Pilot head unit bought as salvage. After pulling the BR/EDR link keys from the stereo, the team could pose as the head unit to any phone that had previously paired with it. The handset assumes it is reconnecting with the vehicle and restores the access it once granted, including hands-free calling, contact and call-log permissions, and messaging profiles.
From there, an attacker can silently read SMS one-time passwords, record calls, or wake the phone’s voice assistant, and the team succeeded in several of these scenarios even when the phone was locked. Data recovered alongside the keys, such as names, addresses, GPS breadcrumbs, and lists of paired gadgets, makes it easy to pick a specific victim rather than gamble on a random one.
Millions of used cars pass through auctions and resellers with their infotainment systems never wiped, so stale pairing state is common. The research team says the practical defenses are simple: unpair phones before selling and factory-reset the stereo, while automakers should clear pairing keys automatically when ownership changes.
The finding stands apart from the usual keyless-entry theft stories because the target is the driver’s digital identity, not the vehicle. The attack chain was presented live at the VehicleSec ’26 demo session in Baltimore.