Automatic Transmission – A Data-privacy Study Of Connected Vehicles
AIThis post was created with the assistance of artificial intelligence (AI).

TL;DR

Prime Big Deal Days · Oct 6–7Offer from Amazon

Get garage and car supplies delivered free — and shop member deals

  • Fast, free delivery on millions of items
  • Access to Prime Big Deal Days deals on October 6–7
  • Prime Video, Amazon Music and more included
Start your free Prime trial Free trial for eligible customers · Cancel anytime
As an affiliate, we earn on qualifying purchases.

Northeastern University researchers, working with Consumer Reports, tested 21 late-model vehicles and 30 companion apps between October 2024 and August 2025. They report that 19 vehicles contacted at least one third party over Wi-Fi, while seven apps sent sensitive identifiers to third-party companies. The findings map observed data flows, but do not establish what recipients did with the data or represent every connected vehicle.

Northeastern University researchers working with Consumer Reports say they found third-party network traffic from 19 of 21 tested vehicles and sensitive identifiers sent to third parties by seven of 30 companion apps. The study offers a measured look at how connected-car services communicate beyond the vehicle and manufacturer, raising questions about what personal information reaches outside companies.

The research team tested 21 late-model vehicles from 19 brands and their associated apps in a controlled setting between October 2024 and August 2025. Consumer Reports provided access to its purchased test fleet. The researchers examined two points in the system: network communications from the vehicles and traffic sent by manufacturer-provided smartphone apps.

For vehicle tests, the team monitored Wi-Fi traffic during stationary idle periods, after carrying out vehicle functions, and during driving. The researchers could identify network destinations, but said vehicle packet contents were encrypted, limiting what they could read. They also put 11 electric vehicles in a Faraday tent to block cellular signals and tested whether traffic shifted to Wi-Fi.

For app tests, researchers paired 30 apps with vehicles and used test iPhones to capture and decrypt app network traffic. They report that seven apps transmitted sensitive identifiers to third-party companies, and that five sent a vehicle identification number, or VIN, along with other personally identifiable information. These are observations from the tested sample and experimental setup, not a count of all vehicles or apps on the market.

At a glance
reportWhen: Study tests conducted October 2024 to A…
The developmentA Northeastern University research team has published findings from a large-scale study measuring third-party data flows from connected vehicles and their companion apps.

Where Car Data Leaves the Vehicle

The findings matter because connected vehicles and their apps can communicate with outside services as part of features such as remote access, location services and charging information. The researchers’ measurements indicate that third-party connections occurred in much of the vehicle sample and that some apps sent identifiers that could be associated with a person or vehicle.

The study identifies network destinations and certain data flows; it does not, by itself, show how a recipient used, stored or shared the information after receiving it. The research report says consumers have limited control once information has left a device and notes that some data may be shared onward. That broader concern should be distinguished from what the experiments directly observed. For drivers, the work highlights the gap between using a connected feature and knowing which companies may receive related data.

Amazon

vehicle Wi-Fi privacy protection device

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

How Researchers Measured Car Traffic

The project describes itself as a large-scale measurement study of the connected-vehicle ecosystem and was conducted by privacy, security and networking researchers at Northeastern University in partnership with Consumer Reports. The report says more than 75% of vehicles sold globally have built-in connectivity, though the study’s direct testing covered a U.S.-market sample rather than a global fleet.

The researchers used a custom Wi-Fi access point to log vehicle traffic destinations. Because that traffic was encrypted, they could not inspect the contents of vehicle packets using this method. For apps, they tested one at a time on cleaned test phones, accepted the permissions requested during setup and use, and exercised available functions. The report says the work is peer reviewed and is listed for publication at IMC ’26.

“19/21 vehicles tested send traffic to at least one third party.”

— Northeastern University research team

What the Measurements Cannot Show

The study’s sample of 21 vehicles and 30 apps cannot establish how every automaker’s current models or software behave. The available report summary does not identify the manufacturers or third-party domains behind each finding, detail every identifier observed, or state whether the tested traffic was tied to particular app settings or account choices.

Vehicle Wi-Fi traffic was encrypted, so researchers recorded destinations without reading packet contents. The app traffic was captured and decrypted under the study’s test conditions, which included granting requested permissions and manually using app features. The report summary also does not establish what third parties did with received information, whether data was sold, or how long it was retained. Those points remain outside the findings presented here.

Publication and Further Scrutiny

The research team says the peer-reviewed paper is scheduled for publication at IMC ’26 and frames its work as an initial step toward improving visibility into connected-vehicle data flows. The full paper and any additional study materials may provide more detail about the tested vehicles, app behaviors, domains and disclosure process.

Further independent measurements would be needed to determine whether the reported patterns persist across more brands, models, software versions and user settings. The study’s central next step is continued scrutiny of what vehicles and companion apps transmit, who receives it, and how manufacturers respond to those findings. The report material provided does not specify a timetable for additional testing or responses from individual manufacturers.

Key Questions

How many vehicles and apps did the study test?

The researchers tested 21 late-model vehicles from 19 brands and 30 companion apps between October 2024 and August 2025.

What did the researchers find about third-party data flows?

The report says 19 of 21 vehicles sent traffic to at least one third party over Wi-Fi. It also says seven of 30 apps sent sensitive identifiers to third-party companies, while five sent a VIN and other personally identifiable information.

Does the study show what third parties did with the data?

No. The reported measurements identify some network destinations and app data flows, but the summary does not establish how recipients used, retained or shared the information after receiving it.

Does the result apply to every connected vehicle?

No. The findings come from a specific sample of vehicles and apps tested under controlled conditions. They do not establish the behavior of every model, manufacturer, software version or app.

When is the research paper expected to appear?

The research website says the peer-reviewed paper will be published at IMC ’26. The supplied material does not give a more specific publication date.

Source: hn

HALLOWEEN

Halloween Picks

As an affiliate, we earn on qualifying purchases.

You May Also Like

Killing With A Car Costs $1.6M, California Requires Drivers To Carry $30K

California requires drivers to carry $30,000 insurance, but the average cost of a fatal car crash is $1.6 million, raising questions about adequacy.

NTSB Issues Investigative Update On B-767 Runway Excursion Accident In Miami

The NTSB has issued an investigative update on the B-767 runway excursion at Miami International Airport, with details still emerging about the cause.

Bicycle Trapped Under Light Rail After Collision Between Rider And Train – KING5.com

A cyclist was hit by a light rail train in Seattle, resulting in the bicycle becoming trapped beneath the vehicle. Authorities are investigating the incident.

Removing the modem and GPS from my 2024 RAV4 hybrid

A detailed report on the confirmed removal of the modem and GPS from a 2024 RAV4 Hybrid, exploring what functions are affected and why it matters for privacy.