zzdcar
Home
/
Reviews
/
Culture
/
Researchers Hacked California's Digital License Plates, Gaining Access to GPS Location and User Info (Update)
Researchers Hacked California's Digital License Plates, Gaining Access to GPS Location and User Info (Update)-June 2024
2024-02-19 EST 22:12:00

Image for article titled Researchers Hacked California's Digital License Plates, Gaining Access to GPS Location and User Info (Update)

managed to hack into California’s new , which are sold and managed by tech company . The digital plates, called , went on sale in California late last year, but it was only a matter of time before found a backdoor into Reviver’s systems.

Luckily, the white hats got there first by gaining full “super administrative access” via the website, according to . This allowed the team of researchers to track the location of all cars using the plates, access all user records and even change some of the text shown on the digital plate displays.

This article was originally published on Monday, January 9th at 06:30pm EST. It has been updated with a statement from Reviver following the discovery of the bug, which the company says has been patched.

Bug bounty hunter Sam Curry how the team started probing Reviver’s mobile app first, then the website. The team became interested in Reviver due to the company’s ability to track the digital plates — and any car wearing one.

Image for article titled Researchers Hacked California's Digital License Plates, Gaining Access to GPS Location and User Info (Update)

Curry says a vulnerability in the Javascript of the website let the team change an account type from a regular user to an administrator, giving them access to GPS location and all information of registered users: this info includes “vehicles people owned, their physical address, phone number, and email address.” On top of that, the bug gave access to the same permissions and info of dealer fleets using digital plates:

Since our administrator account theoretically had elevated permissions, our first test was simply querying a user account and seeing if we could access someone else’s data: this worked!

We could take any of the normal API calls (viewing vehicle location, updating vehicle plates, adding new users to accounts) and perform the action using our super administrator account with full authorization.

At this point, we reported the vulnerability and observed that it was patched in under 24 hours. An actual attacker could remotely update, track, or delete anyone’s REVIVER plate. We could additionally access any dealer (e.g. Mercedes-Benz dealerships will often package REVIVER plates) and update the default image used by the dealer when the newly purchased vehicle still had DEALER tags.

The bug also allowed the researchers to update the status of any digital CA plate to “STOLEN,” which could alert police and possibly send them after a car falsely labeled as the object of . Researchers said they could also change the slogan or text at the bottom of the plate — which users can change at will — but the team didn’t say that they could change the actual license plate number.

Even so, the bug found on the Reviver site could’ve given someone an alarming amount of information and control over the digital plates. As Curry notes, Reviver patched the bug within 24 hours after it was reported; the company shared a statement with Jalopnik saying a subsequent investigation found that the “potential vulnerability” had not been misused, nor had any user data been leaked. From Reviver:

We were recently contacted by a cybersecurity researcher regarding potential application vulnerabilities in the auto industry. Our team immediately investigated this report, met with the researcher, and, out of an abundance of caution, engaged leading data security and privacy professionals to assist.

We are proud of our team’s quick response, which patched our application in under 24 hours and took further measures to prevent this from occurring in the future. Our investigation confirmed that this potential vulnerability has not been misused. Customer information has not been affected, and there is no evidence of ongoing risk related to this report. As part of our commitment to data security and privacy, we also used this opportunity to identify and implement additional safeguards to supplement our existing, significant protections.

Cybersecurity is central to our mission to modernize the driving experience and we will continue to work with industry-leading professionals, tools, and systems to build and monitor our secure platforms for connected vehicles.

Image for article titled Researchers Hacked California's Digital License Plates, Gaining Access to GPS Location and User Info (Update)

Comments
Welcome to zzdcar comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
Culture
Watch ABS Fail When MotorWeek Tests A 1997 Chevy S-10
Watch ABS Fail When MotorWeek Tests A 1997 Chevy S-10
MotorWeek’s is some of the on the internet. The long-running automotive news magazine has a treasure trove of tests after being on the air for over 40 years. Where else can you find detailed instrumented testing of long-forgotten cars like the or a ? MotorWeek’s recent Retro Review upload is...
Jun 25, 2025
I Entered My Lifted Miata In A Real Off-Road Race, Here's What Happened
I Entered My Lifted Miata In A Real Off-Road Race, Here's What Happened
I have two automotive loves: The first is the Miata, the second is off-road racing. For a while I raced air-cooled Volkswagens in the deserts of California and Nevada and I was lucky enough to co-drive in a class 11 stock bug in the Baja 1000 a few years...
Jun 25, 2025
I Can't Get Enough Of This YouTuber Who Builds Tiny, Fully Functional Scale-Model Cars
I Can't Get Enough Of This YouTuber Who Builds Tiny, Fully Functional Scale-Model Cars
I love tiny, of . I have a that is roughly half the size of a normal cat, and she’s perfect. I own a 2013 , which is like the miniature version of a normal-sized vehicle (at least here in Texas) — but beyond that, I also own a Hot...
Jun 25, 2025
2024 Kia EV9: What Do You Want To Know?
2024 Kia EV9: What Do You Want To Know?
At long last, we are about to get behind the wheel of for the first time. Sure, , and sure, , and sure , but hey — what can you do? Anyway, before we get behind the wheel of this three-row electric beast, we want to know what you...
Jun 25, 2025
Toyota Is Moving A Prewar 700-Ton Press Machine Halfway Around The World
Toyota Is Moving A Prewar 700-Ton Press Machine Halfway Around The World
closed its São Bernardo Plant in November 2023, marking the end of its first overseas production facility. The closure caps off a period of continuous car production in São Paolo, , lasting over 60 years. The plant was home to a Komatsu 700-ton press that predates itself. And now...
Jun 25, 2025
Subaru Had It Right All Along
Subaru Had It Right All Along
When first came to the United States, it sold small funky cars that were decidedly un-American. As the company grew its own identity and became more established in the U.S., it became the first automaker to offer an all-wheel-drive passenger car in 1975. Subaru was also an early-adopter of...
Jun 25, 2025
Copyright 2023-2025 - www.zzdcar.com All Rights Reserved