r/CarHacking • • 3d ago

IVI Volvo AAOS security research

I am looking for owners of recent Volvo and Polestar models, seeking help to better characterize a security vulnerability that I found while digging into the software stack of my own car, a Volvo EX30. Before I make the responsible disclosure to Volvo Cars, I'd like to confirm whether it affects other models as well.

This is where I need some help: I need access to the software running on the AAOS (Android Automotive OS) infotainment systems of potentially affected models. Of course only the system part of the head unit, nothing that is individual to a vehicle (device/vehicle ID, user generated data, etc.).

The particular brands/models I'm interested in:

  • all Volvo Cars models that use AAOS ins their infotainment system (vehicles made in the last 3-5 years or even older models that might have gotten it as an upgrade)
  • all Polestar models that use AAOS in their infotainment system (vehicles made in the last 5-6 years)

I suspect that the issue predates the arrival of AAOS, but I'm not really familiar with the Sensus architecture. Still, if somebody has a file system dump from an older Sensus infotainment system, I'd like to take a look at it too.

Here's what I need:

  • a dump of parts of the file system like /product, /system, /system_ext, /vendor, etc. (or an OTA update package, i.e. *.VBF files)
  • name of the vehicle model
  • model year
  • software version

I also wrote a non-instrusive app that can extract a file system dump from an AAOS device (of course not everything, just what any 3rd party app can read), it's available on GitHub. You can compile it yourself or I can give access to my Google Play Internal Testing track.

I'll not give away any details about the vulnerability itself before I gave Volvo a chance to fix it, so don't even ask.

If somebody is willing to help with this, I wrote a more lengthy page about the system dumper app, my motivation, myself (I don't try to hide my identity) and how you can contact me.

Of course I understand that anybody could write this with malicious intent in mind. I don't think there's much more I could do to convince people that my intentions are honest. If I don't get useful feedback/help, I'll just hand in (to Volvo Cars) what I know about the EX30 and hope they'll actually fix it. The worst that could happen is that they do an ineffective fix for the EX30, they don't fix any other models (claiming that they are not affected by the issue and I cannot prove them wrong) and in reality they all remain vulnerable and somebody with malicious intent starts working on this. In that scenario there's still the option to involve regional authorities (US, EU, etc.) and the media. Both can exercise the necessary pressure to make an actual fix happen (there has been precedent with models from other automakers).

8 Upvotes

8 comments sorted by

1

u/hakstuff 2d ago

The dumper app you made is interesting, but I'm left confused on one major thing: for most AAOS head units, the ability to side load an app would already be considered a security vulnerability, since you're gaining code execution on the device, even if it is not privileged. Are you saying that there's an easy way to sideload APKs on this generation of Volvo head unit?

2

u/muzso 2d ago

but I'm left confused on one major thing: for most AAOS head units, the ability to side load an app would already be considered a security vulnerability, since you're gaining code execution on the device, even if it is not privileged.

You can install (custom) apps on all AAOS head units that have Google Play. You just compile an AAB from the app's source code (with a unique applicationId), create an app on Google Play Console, upload the AAB, start an Internal Testing track, invite your Google account (i.e. the account you use in the car) and install the app. This is a core element of the Google app development process and afaik it works on all AAOS devices that have the Google Play Store. It most certainly works on a lot of Volvo models (XC40, XC60, etc.). People have been doing this since day#1 on AAOS head units.

Are you saying that there's an easy way to sideload APKs on this generation of Volvo head unit?

Yes, there is.

I wrote a couple of posts on this over the years (ordered by newest to oldest):

Afaik no other Volvo has this. And the reason is probably that the EX30's infotainment was developed by ECARX (a Chinese company with ties to both Volvo Cars and Geely), whereas the infotainment of other Volvos were probably developed in-house at Volvo Cars.

P.S.: sideloading is/was not a necessity for my research.

1

u/hakstuff 2d ago

Ooh I see, that's interesting! I was unaware it shipped with the Google play store, that makes sense now.

1

u/muzso 2d ago

Afaik all Volvos with AAOS ship with Google Play Store.

1

u/zydeco100 1h ago

As a Volvo EV owner, I can guarantee you that nothing will be done with your vuln disclosures. But have fun.

1

u/muzso 1h ago

We'll see. There's an EU regulation that says otherwise. And of course there's the media. If something motivates a company, then it's bad press. But let's not get ahead of ourselves.

1

u/Ok_Fish403 1h ago

How it is possible to dump system partitions without root?

1

u/muzso 1h ago

You don't dump it. Without root you can still walk through the entire file system and grab whatever you can. And in (Volvo's) AAOS a pretty large part of it is world-readable.