Grand Theft Tesla: Android App Hack Unlocks, Starts Car

Tesla drivers using the company's Android app to control their cars could be facing serious safety concerns, according to security researchers who demonstrated in a video that anyone with a laptop and Android hacking skills can exploit the app to unlock, start and drive away a stranger's Tesla.

Credit: Tesla

(Image credit: Tesla)

In a blog posting and YouTube video from last week, researchers at Norwegian computer-security firm Promon showed how they could track and unlock Tesla vehicles. They could even go as far as stealing the vehicles, using a Tesla app feature that lets owners drive the car without even having their key fob on them.

The problem exists in part, the Promon blog post said, because many Android phone manufacturers aren't delivering operating-system security patches needed to prevent cyber attacks. More current versions of Android such as Android 6 Marshmallow or Android 7 Nougat make the attack more difficult, but not impossible.

MORE: Best Android Antivirus and Security Apps

This specific exploit used a malicious app downloaded from the Google Play app store on a non-rooted 2014 Samsung Galaxy A5 running Android 5.0 Lollipop, the most recent version of the OS compatible with that model of phone. These Tesla owners would have to unknowingly download such a malicious app, but that happens frequently enough, even in the official Google Play app store.

The Tesla Model S sedan.

The Tesla Model S sedan.

Furthermore, this exploit applies only to Tesla drivers who have set up the Android app so that they don't need to enter their login credentials every time they use it. Doing so creates an authentication token that's valid for 90 days, but which the Tesla app does not protect with encryption. Many kinds of Android malware could copy and re-use the Tesla authentication token to gain access to the car.

However, the malware needs to also capture the user's actual username and password to start the car's engine. Again, many kinds of Android malware could do so.

This type of mobile-app vulnerability isn't limited to the Tesla app. The lack of security updates could allow hackers to access other Android apps, Promon says, but the ability to take control of a Tesla owner's car is particularly disturbing and potentially dangerous for more than just a vehicle's owner.

To prevent your Tesla from disappearing from your driveway, disable the feature that lets you go 90 days without logging into the Android app. Update your phone's operating system to Marshmallow or Nougat. (If you can't, but you own a Tesla, then you can afford a new phone.) Install and run Android security software that can catch and block most kinds of Android malware. And be very careful when installing Android apps you're not familiar with.

TOPICS

Althea Chang is Associate Director of Content Development for Consumer Reports and was previously a Senior Writer for Tom's Guide, covering mobile devices, health and fitness gadgets and car tech. 

Latest in Android Phones
Samsung Galaxy S25 Edge next to Galaxy S25 Plus
Samsung Galaxy S25 Edge vs. Galaxy S25 Plus: Everything we know so far
Samsung Galaxy S25 Ultra vs S25 Plus vs S25
Satellite messaging on Google Pixel 9 and Samsung Galaxy S25 just landed on 3 more carriers
back of Iris Pixel 9a
The Google Pixel 9a is lacking one of the Pixel 9’s best safety features — here’s what we know
vivo x200 ultra camera array
Vivo’s next premium phone could have a camera unlike anything we’ve seen before — here’s how
Google Pixel 9a with thumbs up and thumbs down icons
Google Pixel 9a — 5 reasons to buy and 3 reasons to skip
Pixel 9 Pro XL held in the hand with price drop badge.
Not a typo! This epic deal makes the flagship Pixel 9 Pro XL the same price as the budget Pixel 9a
Latest in News
Nintendo Switch 2
Nintendo Switch 2 rumored specs — here’s what we know so far
iPhone 17 Pro render
iPhone 17 Pro — 7 biggest rumored upgrades
CAD renderings of the Google Pixel 10 Pro XL
Pixel 10 leak could be good news for all Android phones
A magnifying glass on top of the Steam logo in a web browser
Valve just pulled a malicious game demo spreading info-stealing malware from Steam
Lewis Hamilton of Great Britain and Scuderia Ferrari looks on during Sprint Qualifying ahead of the F1 Grand Prix of China at Shanghai International Circuit in Shanghai, China, on March 21, 2025. (Photo by Song Haiyuan/Paddocker/NurPhoto via Getty Images)
How to watch Chinese Grand Prix 2025 online – stream F1 without cable, qualifying highlights
NYTimes Connections
NYT Connections today hints and answers — Saturday, March 22 (#650)
  • Bob_127
    The easier it is to hack into and "steal" a car, the easier it is to instantly locate it once it is stolen, and also to disable it.
    Reply