Arstechnica Connected Cars Compromise Driver Privacy: Major Data Sharing Exposed
Article Content
- •Connected cars transmit personal data to major tech firms.
- •All tested car brands failed privacy assessments by Mozilla.
- •Sensitive data collected includes health information and driving behavior.
A study by Northeastern University and Consumer Reports reveals that connected cars share extensive personal data with major tech companies, including Amazon, Google, and Microsoft. The research tested 21 vehicles, finding that nearly all sent data such as locations, VINs, and even personal identifiers to third parties. Mozilla's *Privacy Not Included report also highlighted that all 25 major car brands reviewed failed privacy tests, collecting sensitive information like health data and facial expressions. The data is often used for targeted advertising and can lead to privacy violations for drivers and passengers. This alarming trend indicates that consumers are largely unaware of the extent of data collection and sharing by their vehicles. The study emphasizes the urgent need for stricter regulations and transparency from automakers regarding data practices.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track BMW in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…