1. Home
    2. Car News
    3. BYD
    4. Shark 6
    5. News

    BYD's own Shark 6 hacking investigation reveals ‘software defect’

    Changes will be made to some aspects of BYD’s software after a cybersecurity test exposed vulnerabilities, while the lab responsible for the Shark 6 hacking demonstration is calling for a cybersecurity star rating.

    Damion Smy

    Damion Smy

    Deputy News Editor

    Damion Smy

    Damion Smy

    Deputy News Editor

    BYD Australia will make upgrades to the software in its Shark 6 plug-in hybrid ute following its own internal investigation into the hacking of one of its dual-cabs for ABC current affairs program Four Corners.

    The report made headlines after a BYD Shark 6 ute was accessed by Canberra-based Fortify Labs, which accessed the vehicle’s infotainment software to monitor its location and even tapped into phone calls made in the car.

    Four Corners also showed the vehicle’s headlights and windscreen wipers being accessed remotely by professional hackers, demonstrating vulnerabilities in the vehicle’s software.

    Following the program, which was broadcast on September 21, 2026, BYD Australia launched a formal internal investigation into the claims.

    Hacker_AI_CarExpert

    The Chinese automaker said the investigation found the ability to access the vehicle was the result of a ‘software defect’ in its infotainment software, exploited using an ‘Android Debug Bridge’ (ADB), a tool which enables access to Android devices.

    The BYD Shark 6 uses a ‘DiLink’ infotainment system based on Android software, used in other BYD and Denza models sold in Australia, although it's heavily customised and developed specifically by BYD.

    "The researcher exploited a software defect to enable the ADB and subsequently install an untrusted third-party application," said BYD in a statement.

    It said special tools were required to access the ADB, and the company’s engineers were able to replicate the actions shown on Four Corners as part of the investigation.

    However, BYD said the initial access to the vehicle required physical access and couldn't be performed remotely.

    “When the application requested access to certain information or functions, such as the vehicle’s location or microphone, the infotainment system displayed a permission prompt,” the BYD statement said.

    “The requested permissions could only be granted after the user manually approved the request through the infotainment interface.

    “The corrective action will address the identified ADB-related software issue and remove the unintended pathway that allows ADB to be enabled through the infotainment system user interface, thereby eliminating the access path identified during the investigation,” the statement said.

    BYD will deploy an over-the-air software update for the Shark 6 "only once the updated software has undergone rigorous validation [testing]". It says it's also investigating if this update will be required for other models in its lineup.

    The other area BYD investigated was access to the vehicle’s controller area network (CAN), or ‘CAN bus’. A CAN bus is the internal communications network that allows the vehicle’s electronic control units and other systems to communicate with each other, essentially acting as the vehicle’s nervous system.

    This is how Fortify Labs remotely accessed the headlights and other functions of the Shark 6 for Four Corners.

    “BYD’s technical analysis has confirmed that the demonstrated control of the vehicle’s headlights and windscreen wipers required direct physical access to the vehicle’s internal CAN bus by tapping into the vehicle wiring,” the automaker said.

    “This method requires physical intervention on the target vehicle and is limited to the individual vehicle that has been physically accessed."

    The company says it has initiated a "dedicated risk assessment" to assess the "necessity and technical feasibility of additional measures relating to CAN message authenticity, integrity and freshness verification". It says it'll use findings to "further review and strengthen relevant cybersecurity controls and development processes".

    “BYD has implemented security measures for the OBD interface, including device authentication and physical isolation, and has established corresponding cybersecurity safeguards in accordance with the requirements of UN R155," the company said.

    UN R155 requires automakers to operate a Cyber Security Management System (CSMS), which identifies potential vehicle cybersecurity risks and requires appropriate measures to manage and mitigate those vulnerabilities.

    Draft Australian Design Rules ADR 115 and ADR 116, designed to better regulate vehicle security, are based on UN R155 and UN R156, but timing for the introduction of the new ADRs has not yet been finalised.

    Fortify Labs has issued a statement of its own, saying its objective for the Four Corners episode was to “Simulate the remote access a car manufacturer has to a connected vehicle and demonstrate how this access could be abused”.

    “It is important to highlight that at no point was this investigation about gaining initial access to the vehicle," the organisation said.

    A hand holding a smartphone displaying a Skoda connected services app with car discovery content and vehicle images on screen

    “The required access was already implied, given we were simulating a manufacturer’s access to a connected vehicle. Manufacturers have the ability to reach into their vehicles remotely, run individual commands and deliver over-the-air (OTA) updates.”

    Fortify Labs did commend BYD for well-implemented security in parts of the vehicle, but said it hoped its demonstration of vulnerabilities would be a catalyst for change, and noted the draft ADRs are a step in the right direction.

    It has called for a cybersecurity star rating for consumers to evaluate the security of connected cars, including data storage and collection.

    “People shouldn’t just blindly trust that vehicle manufacturers are producing safe and secure cars, and this doesn’t only apply to Chinese manufacturers. The same goes for vehicles coming out of the United States, Europe and the rest of Asia. It applies to all vehicle manufacturers,” it said.

    “It’s also worth highlighting that these risks are not faced by Australia alone. This is a global issue, and other countries should be concerned.”

    MORE: 'Urgent' calls for greater transparency on data collection following report on Chinese car hacking

    Ready to find the right new car at a great deal?

    Research cars in our Showroom, compare your options or let our New Car Specialists do the running around to find you a great deal.

    Damion Smy

    Damion Smy

    Deputy News Editor

    Damion Smy

    Deputy News Editor

    Damion Smy is an award-winning motoring journalist with global editorial experience at Car, Auto Express, and Wheels.

    Read more

    You might also like