Articles & Research

Briefing

The Jeep hack: when a software flaw becomes a safety recall

A 2015 remote hijacking of a Jeep Cherokee triggered a 1.4 million-vehicle recall and redefined automotive engineering as a safety-critical software discipline.

Marcus Reyes

Contributing Editor, Software Engineering, American Computer Society

August 2015 · 6 min read

Autonomous test vehicle with roof-mounted lidar on a city street at dusk
Autonomous test vehicle with roof-mounted lidar on a city street at dusk

In July 2015 security researchers remotely disabled a Jeep Cherokee's transmission on a public highway, proving that a car's software could be attacked like any networked computer. The response — a 1.4 million-vehicle recall — marked a turning point for automotive engineering standards.

A journalist, a highway and a kill switch

In a widely read Wired feature published 21 July 2015, journalist Andy Greenberg described driving a Jeep Cherokee at 70 mph outside St Louis while security researchers Charlie Miller and Chris Valasek, working remotely, took control of the vehicle's air conditioning, radio, windshield wipers and ultimately its transmission, cutting power on the highway.

The pair had spent months studying Chrysler's Uconnect infotainment system, finding they could exploit a cellular connection to reach the vehicle's internal network from anywhere on the carrier network, with no physical access required.

“A journalist lost control of his transmission at 70 mph — and the industry finally admitted that a car is a computer network with wheels attached.”

From proof-of-concept to recall

The demonstration was not merely academic. On 24 July 2015, three days after the story ran, Fiat Chrysler Automobiles announced a formal recall of approximately 1.4 million vehicles in the United States to patch the vulnerability — one of the first major product recalls issued specifically in response to a cybersecurity finding rather than a mechanical defect.

The incident accelerated industry-wide recognition that modern vehicles are distributed computer networks on wheels, with dozens of electronic control units communicating over a CAN bus that was never designed with adversarial actors in mind.

  • Wired's account of the remote takeover published 21 July 2015.
  • Fiat Chrysler recall of roughly 1.4 million vehicles announced 24 July 2015.
  • Vulnerability traced to the Uconnect infotainment system's cellular connectivity.

A discipline forced to mature

The Jeep case pushed automakers and suppliers toward practices long established in aviation and industrial control — network segmentation between infotainment and safety-critical systems, secure over-the-air update mechanisms, and coordinated vulnerability disclosure programmes. It also lent momentum to the Auto-ISAC, an information-sharing body for automotive cybersecurity established in 2015.

For software engineers entering the automotive sector, the episode reframed the job: a bug in an infotainment unit was no longer a customer-experience defect but a potential threat to human life, subject to the same rigour long demanded of brakes and airbags.

What the Society recommends

The Society holds that software controlling physical, safety-critical systems must be engineered and audited to the same standard as the mechanical components it now controls or replaces.

  • Apply safety-critical engineering practices — including formal testing and independent security review — to any system with physical-world consequences.
  • Segregate infotainment and telematics networks from braking, steering and powertrain control by design.
  • Participate in coordinated disclosure and industry information-sharing rather than treating vulnerabilities as reputational threats.
  • Recognise that professional accountability extends to embedded and automotive software, not only to conventional IT systems.
CybersecuritySoftware engineeringSpace and transport

Join the professional body behind this work

ACS members receive our research first, free CPD and ethics modules every year, and a route to professional registration assessed by their peers.

Become a member