Hacker News new | ask | show | jobs
by darknavi 1 day ago
> November 3, 2025: Reported.

> November 10, 2025: No response, followed up.

> November 17, 2025: No response, followed up and copied some additional people on the thread.

> November 20, 2025: It was no longer possible to access any of the internal APIs. The primary vulnerability was now fixed.

> July 27, 2026: Published

Quite the generous timeline on this person's behalf.

2 comments

And terrible (non-)response from VECV, if they have any interest in receiving timely disclosure from future researchers.
reminder, these vendors like Volvo etc., don't really want you to report vulns, you should just sell them to a broker instead and get some actual money as well, it's a win win.
I don’t know why particularly here over elsewhere, but this thought really makes me feel disappointment in the whole chain of humans responsible for the cost optimization away of product integrity.

Though in this case, with all the tracking being thrown into newer cars, maybe a bit of a gap is a good thing for the future. Jailbreaking vehicles would be a cool thing to see become widespread.

there's no point in being moral when these companies with their immense resources will just ignore you or refuse to give a measly bounty

things won't change until they have to make an effort

This. If they don’t feel pressure to pay, they won’t.

More people should make them pay.

reminder, Volvo is Chinese.
Are you thinking about Volvo cars? There are two Volvo companies, Volvo cars and Volvo group. This seems to be about Volvo group which makes commercial vehicles like trucks and busses.
Also the exploit is not directly via volvo but with a third party
How so? Sources?
That would be Volvo cars. tfa is about Volvo group, which is Swedish and makes among other things Volvo trucks. (Or HGVs as they might be called in Europe)
Oh, fair. I assumed this was consumer cars.