CarPlay at Risk: Unveiling Security Threats of Third-Party Infotainment Adapters

Jun Yeon Won, Wenzhuo Wang, Keith Redmill, and Zhiqiang Lin, Ohio State University

Modern vehicles offer extensive functionality through smartphone integration, enabling users to stream music, make calls, and access various applications. Some features, such as navigation, require a direct connection between the vehicle and the smartphone via Bluetooth or a USB cable. Android devices utilize Android Auto for this connection, while iOS devices rely on Apple CarPlay. For safety reasons, certain functions, such as playing live videos while driving, are deliberately restricted. However, aftermarket in-vehicle adapters have emerged that bypass these restrictions, enabling video playback on the in-vehicle infotainment (IVI) system. Notably, some adapters can establish CarPlay connections despite not running the iOS operating systems. To understand these mechanisms, we conducted a reverse engineering analysis of one such adapter to investigate how non-iOS devices exploit CarPlay compatibility. Additionally, we performed a differential analysis comparing this unauthorized connection with legitimate CarPlay connections between an iPhone and an IVI system. This paper examines the technical aspects of unauthorized device integration with CarPlay, identifies potential security threats, and proposes mitigation strategies to enhance the security of future CarPlay implementations.

Open Access Media

USENIX is committed to Open Access to the research presented at our events. Papers and proceedings are freely available to everyone once the event begins. Any video, audio, and/or slides that are posted after the event are also free and open to everyone. Support USENIX and our commitment to Open Access.

BibTeX
@inproceedings {309182,
author = {Jun Yeon Won and Wenzhuo Wang and Keith Redmill and Zhiqiang Lin},
title = {{CarPlay} at Risk: Unveiling Security Threats of {Third-Party} Infotainment Adapters},
booktitle = {3rd USENIX Symposium on Vehicle Security and Privacy (VehicleSec 25)},
year = {2025},
isbn = {978-1-939133-49-6},
address = {Seattle, WA},
pages = {143--159},
url = {https://www.usenix.org/conference/vehiclesec25/presentation/won},
publisher = {USENIX Association},
month = aug
}

Presentation Video