Your Car’s Companion Apps Are Sharing VIN, Location, and Personal IDs with Advertising Trackers
What Happened — Researchers examined 21 vehicles (model years 2022‑2025) and 30 companion mobile apps. Network captures showed that 19 vehicles and 7 apps routinely sent VINs, precise location, and email addresses to third‑party advertising and tracking domains.
Why It Matters for Trust & Control Assurance
- Continuous control‑assurance programs must verify that data‑handling practices of third‑party services are documented, consent‑driven, and auditable.
- The finding highlights a gap in the privacy and third‑party oversight control objective—organizations need evidence that personal identifiers are not unintentionally exposed to external trackers.
- Verisq’s CookiePLUS Privacy capability helps collect and demonstrate consent records, data‑flow mappings, and third‑party risk evidence for audit readiness.
Who Is Affected – Automotive manufacturers, connected‑vehicle platform providers, and users of companion mobile apps (consumer‑facing).
Recommended Actions
- Map all data flows from vehicle telematics and apps to third‑party endpoints.
- Validate that consent mechanisms meet the “freely given” standard and can be revoked without loss of core safety functions.
- Capture evidence of third‑party contracts, data‑processing agreements, and privacy impact assessments for audit readiness.
Technical Notes – The study used passive network monitoring (Wi‑Fi and cellular) while vehicles were stationary, in motion, and when apps were active. No specific vulnerability (CVE) was identified; the issue is systemic data‑sharing behavior. Source: Malwarebytes Labs