Back
Study finds connected vehicles contact third-party advertising and tracking domains
SiTech AI Team3 min read

Study finds connected vehicles contact third-party advertising and tracking domains

A study of 21 U.S. vehicles found that 19 contacted third parties over Wi-Fi, while 7 of 30 companion apps sent sensitive identifiers to third parties linked to advertising and tracking.

What the study examined

Researchers investigated 21 vehicles from the U.S. market and 30 manufacturer companion apps in a controlled environment between October 2024 and August 2025. They examined data flowing to and from vehicles and apps through Wi-Fi and cellular connections, focusing on personal information, the recipients of that information, and manufacturer responses.

For vehicle tests, a Raspberry Pi served as a custom access point, and tcpdump recorded traffic. The researchers could identify destination domains but not inspect encrypted packet contents. They performed stationary idle and activity tests and drove vehicles at 5 to 45 mph. They also placed 11 electric vehicles inside a car-sized Faraday tent that provided about 93 dB of attenuation to test whether blocked cellular traffic moved to Wi-Fi.

Sensitive data reached third parties

Nineteen of the 21 vehicles contacted at least one third party over Wi-Fi, including domains associated with advertising and tracking. The study did not cover every U.S. manufacturer, and its results represent a snapshot of the tested vehicles and period.

Seven of the 30 companion apps transmitted sensitive identifiers to third parties associated with advertising and tracking. The identifiers included vehicle identification numbers, email addresses, phone numbers, and precise location. Sending several forms of personally identifiable information to the same party can allow advertisers to build detailed profiles of consumers.

Apps expanded the exposure

Pairing a companion app roughly doubled a vehicle's exposure to advertising and tracking companies on average. In some cases, the app added more than 20 such companies. The researchers reported cases where adding apps to their analysis exposed owners to more than two dozen additional trackers.

The app tests used iPhones with custom root certificates connected to mitmproxy to capture and decrypt network traffic. During installation and login, testers accepted requested permissions, including tracking, location, calendar, Bluetooth, and notifications. They then exercised available functions such as vehicle location, charging station searches, service information, notifications, and remote trunk access.

Manufacturers shifted responsibility

The team disclosed its findings to the manufacturers represented in the study. The responses repeatedly shifted responsibility to consumers, even though owners cannot choose whether their data is shared. Owners who object may have to accept the agreements, stop using connected features such as remote start and companion apps, or stop using the vehicle.

Honda was described as a notable exception because it changed its data collection practices to prevent precise geolocation from being sent to a third party associated with user tracking. Overall, the researchers found a gap between public disclosures and actual data-sharing behavior. They called for better transparency across the connected vehicle ecosystem.

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.