Skip to content
Review Open access

Mapping the landscape of software vulnerabilities in connected vehicles

Sep 2026 · Software quality journal · Vol 34 · 0 citations · 41 references

TL;DR

A survey of automotive software vulnerabilities and associated attack vectors and analyzes the significant changes in security trends is presented and several security recommendations for software engineering teams are provided based on the findings.

Abstract

The increased level of connectivity for vehicles leads to sophisticated and challenging software security concerns for automotive Original Equipment Manufacturers (OEMs) and suppliers. With a Connected Vehicle (CV) communicating with multiple entities (road infrastructure, other vehicles, OEMs, cloud, etc.), new attack surfaces are exposed to intruders. For instance, in 2023, ethical hackers demonstrated remote access to critical vehicle controls like steering and braking through vulnerabilities in infotainment and telematics systems. Several OEMs also reported production disruptions due to ransomware targeting software development infrastructure. Additionally, the current state of the art fails to provide a holistic view of a secure software development process for CVs. This paper presents a survey of automotive software vulnerabilities and associated attack vectors and analyzes the significant changes in security trends. Moreover, the vulnerabilities are tracked across the Software Development Life Cycle (SDLC). We include 413 new automotive software vulnerabilities identified within the last 2 years and 9 months in our study. Additionally, 20 automotive software repositories with 827 vulnerable libraries are identified by scanning sources such as repositories, SBOMs (Software Bill of Materials), images, and manifest files. We provide several security recommendations for software engineering teams based on the findings. Our findings are a step forward to support the maintenance of automotive software quality in terms of security across its entire life cycle.

Read PDF

Similar papers

Conference Sep 2026

Penetration testing of the CAN bus-based XCP protocol for automotive ECMs

A layered test architecture tailored for ECM applications is constructed, security risks of the XCP protocol under unauthenticated and weak-permission scenarios are identified, and engineering-oriented mitigation strategies are proposed.

Ruo-Fei Xing, Ke-Xun He, Bai-Zheng Wang et al. · 0 citations
Review Open access 2026

Convergent Safety-Security Risk Assessment for V2X-Enabled Connected and Autonomous Vehicles: A Comprehensive Survey and Research Roadmap

Connected and Autonomous Vehicles (CAVs) with Vehicle-to-Everything (V2X) communication are transforming transportation systems, but their increasing connectivity and automation introduce critical challenges where safety and cybersecurity intersect. Traditional approaches treat safety analysis through Hazard Analysis a...

Chaima Zaghouani, Mohamed K. Elhadad, Hakim Ghazzai et al. · 0 citations
Review Open access Sep 2026

AI-Enabled Hardware-in-the-Loop Validation for Automotive Cybersecurity: A Review of Cyber Threats, Testbeds, and Intelligent Detection

Cybersecurity has become one of the most critical challenges in the intelligent and connected vehicle ecosystem of today. As modern vehicles become increasingly connected and intelligent, the frequency and sophistication of cyberattacks targeting automotive systems continue to grow at an alarming rate. Ensuring robust...

Farshideh Kordi, Paul Fortier, A. Miled · 0 citations
Preprint Aug 2026

A Roadmap to Available ICS Datasets and Testbeds for Cybersecurity Research

The main objective of this paper is to provide the roadmap of existing ICS cybersecurity datasets, testbeds and digital twins, and provide the identification of research gaps and recommendations on creation of new tools.

Ebtesam S. Alqahtani, Mohammad Hammoudeh · 0 citations
Review Open access Sep 2026

A Comprehensive Review of Cybersecurity Frameworks and Defense Mechanisms for Modbus and HTTP in Industrial Control Systems

Industrial Control Systems (ICS) form the backbone of critical infrastructure, enabling automation and control in sectors such as energy, water, and manufacturing. The convergence of Operational Technology (OT) and Information Technology (IT) has introduced significant cybersecurity challenges, particularly for legacy...

Lukumba Phiri, Mukubesa Kamutumwa · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.