No smashed window. No hotwire. A thief sits in a parking lot with a laptop and two relay devices smaller than a deck of cards. Your car unlocks itself, engine ready. Two separate lines of security research — one targeting the Bluetooth stack inside infotainment systems, the other exploiting the phone-as-key feature built into millions of modern vehicles — have converged on the same conclusion. Bluetooth is the softest entry point on vehicles from Mercedes-Benz, Volkswagen, Skoda, Tesla, and others.
Two Attacks, One Weak Link
Researchers found flaws in both the software running your dashboard and the signal connecting your phone to your car.
PCA Cyber Security discovered four critical vulnerabilities — dubbed PerfektBlue, tracked as CVE-2024-45431 through CVE-2024-45434 — in BlueSDK, a Bluetooth stack embedded in infotainment units across multiple automakers. One user click while in pairing range can hand an attacker remote code execution, according to PCA Cyber Security. From there: location tracking, audio recording, stolen contacts, and in vehicles with poor network segmentation, potential access to powertrain controls. OpenSynergy released patches in September 2024, but those fixes still require automakers to actually push them to your dashboard.
NCC Group’s BLE relay attack works differently. Place one relay device near the owner’s phone — roughly 30 feet away — and another near the car at about 10 feet. The Tesla Model Y the researchers tested unlocked and started without the physical key anywhere near it. Standard Bluetooth tops out around 10 meters, but amplified setups can reach 50–100 meters, roughly the span of a grocery store parking lot. Engine disruption via Bluetooth remains theoretical in most architectures — no documented real-world remote engine shutdowns exist yet — and a separate USENIX study found 128 vulnerabilities across 22 cars from 14 brands, confirming that outdated Bluetooth stacks ship constantly.
“This proves that any product relying on a trusted BLE connection is vulnerable to attacks even from the other side of the world,” Sultan Qasim Khan of NCC Group told Reuters.
Volkswagen has publicly argued that exploitation conditions — specific range, ignition state, user approval — limit real-world risk. Security researchers counter that exploitation thresholds historically tighten as tools become cheaper and more accessible.

The Feature You Never Ordered
Default-on connectivity means the attack surface exists whether you opted into it or not.
Many vehicles ship with passive BLE entry, remote start, and telematics baked into the firmware from day one. The Bluetooth SIG actively promotes phone-as-key adoption as a convenience feature. The security tradeoffs get considerably less airtime. Your car’s attack surface expanded the moment it rolled off the lot — the hardware and base firmware create the exposure regardless of whether you ever activated a premium subscription tier or understood what you were agreeing to. This mirrors the broader risk of secretly tracking users through always-on connected devices.
What You Can Actually Do Right Now
Three concrete steps that reduce your exposure without requiring a cybersecurity degree.
- Disable passive proximity unlock when you’re not using it — NCC Group specifically recommends removing passive features that require no explicit user interaction.
- If you drive a Tesla, enable PIN-to-Drive; even a successful relay attack hits a wall if the attacker can’t enter the PIN to move the vehicle.
- Contact your dealer about infotainment firmware updates tied to BlueSDK patches released in September 2024, since integration timelines vary by brand.
Beyond that, turn off Bluetooth when parked in public spaces and purge paired devices you no longer use — steps that can offer real peace of mind.
Your car shipped with connectivity features most owners never audited, and automakers rarely explain. That silence is the vulnerability.





























