CarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Notification
  • Autonomous Driving
  • Automotive Ethernet
  • BMS
  • ECU
  • EV
  • ISO/SAE 21434
  • Infotainment
  • OTA Updates
  • OBD-II
  • Pwn2Own
  • RCE
  • SDVs
  • TCU
  • UNECE R155
Cybersecurity

St. Paul pulls plate reader cameras after data reached immigration agents

Policy & Compliance

China freezes vehicle software to end patch-later OTA era

Policy & Compliance

NRMA and Lexus Australia push Canberra toward car data law

Policy & Compliance

Quebec report declares car data consent fundamentally broken

Font ResizerAa
CarThreatCarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
Search
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Sign In Sign In
Follow US
© 2026 Carthreat.com. All right reserved.
CybersecurityResearch & Innovation

EvilValet attack uses AOSP test keys to compromise Honda infotainment

Security researcher demonstrates that Honda Civic headunits accept unsigned code via USB through publicly known Android test keys, enabling arbitrary code execution.

CarThreat Staff
Last updated: July 21, 2026 5:33 am
By
ctadmin
2 Min Read
SHARE

Excerpt: Security researcher demonstrates that Honda Civic headunits accept unsigned code via USB through publicly known Android test keys, enabling arbitrary code execution.
A security researcher demonstrated that the infotainment system in 2021 Honda Civic vehicles accepts software updates signed with publicly known Android Open Source Project (AOSP) test keys, enabling arbitrary code execution through physical USB access. The technique, dubbed “EvilValet,” was published June 13 and cited in VicOne’s Q2 2026 Situational Awareness Report as a notable automotive security finding.

The researcher, writing on JuniperSpring, discovered that Honda’s headunit update process relies on the stock AOSP verification logic and leaves the publicly known AOSP test key in the res/keys directory. This means anyone with physical access to the vehicle’s front USB port can prepare a USB drive with a properly formatted update signed with the test key and install arbitrary software on the headunit.

“An attacker has arbitrary code execution on the headunit via the update path,” the researcher explained. The attack requires no conventional root access — no su binary with setuid is needed.

The researcher compared the scenario to an “evil maid” attack, reimagined for automotive contexts. “Imagine a journalist drives to a hotel and leaves their car with the valet,” they wrote. “The valet, who works for a three-letter agency, installs an update via USB. When the car is returned, the journalist doesn’t know the headunit has been modified.”

Honda’s European software update file MRC_EU_SW_v12_4.zip was confirmed to be test key signed, suggesting the issue may extend across multiple regional variants and model years. The researcher also published an open-source tool called ota-builder that automates the preparation of signed update files.

The implications go beyond surveillance. A compromised headunit could potentially serve as a pivot point into the vehicle’s internal networks, affecting CAN bus systems or other safety-critical components. No official Honda response has been published at the time of reporting.

Join Our Newsletter
Subscribe to our newsletter to get our newest articles instantly!
TAGGED:Automotive SecurityCar HackingHondaInfotainmentUSB AttackVulnerability
SOURCES:VicOneTom's Hardware
Share This Article
Facebook Email Copy Link

Follow US

Find US on Social Medias
FacebookLike
XFollow
YoutubeSubscribe

You Might Also Like

PCA finds 345 auto vulnerabilities as high-severity flaws double
Cybersecurity

PCA finds 345 auto vulnerabilities as high-severity flaws double

By
ctadmin
August 1, 2026
My Eicher fleet API flaws exposed 676,000 trucks to takeover
Cybersecurity

My Eicher fleet API flaws exposed 676,000 trucks to takeover

By
ctadmin
August 1, 2026
Cybersecurity

Mercedes Benz Telemetry Data Replaces Manual Road Surveys for Infrastructure Safety

By
ctadmin
July 21, 2026
Cybersecurity

Microchip Adds FOTA and Key Management ICs to Meet Automotive Cyber Regulations

By
ctadmin
June 19, 2026
Cybersecurity

NXP and Quanta Join Forces on Deterministic Zonal Network for SDVs

By
ctadmin
May 22, 2026
Cybersecurity

Stellantis and Microsoft Expand Partnership to Tackle Automotive AI Security

By
ctadmin
May 22, 2026

CarThreat

Intelligence for the EV and automotive security market
  • News
  • Features
  • Spotlight
  • Events
  • About Carthreat
  • Our Mission
  • Services
  • Contact Us
  • OBD-II
  • Automotive Ethernet
  • TCU
  • Infotainment Systems
  • SDVs
  • BMS
  • ECU Security
  • CAN Bus
  • OTA Updates
  • Vulnerabilities
  • Relay Attacks
  • RCE
  • Threat Intelligence
  • Cybersecurity
  • Digital Keys
  • Bluetooth Security
  • ISO/SAE 21434
  • UNECE R155
  • Regulations
  • Data Privacy
  • EVs
  • Autonomous Driving
  • Pwn2Own Automotive

© 2026 Carthreat.com. All right reserved.  Privacy Policy | Legal

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?