Six carmaker apps, four from GM, send VIN and location to ad firms and data brokers
sidjustice_ · x · 2026-10-01
Researchers tested 30 carmaker apps and found six sending the vehicle's VIN—alongside email, phone number, or precise location—to ad, tracking, and analytics companies including Google, Meta, Microsoft, Snap, Adobe, and data broker Acxiom. Four of the six are GM apps: myChevrolet, myCadillac, myBuick, and myGMC. A VIN is a permanent, non-resettable identifier tied to the car, making the leak a long-term tracking risk.
More from Safety
- Awesome list curates agent skills security resources: attacks, defenses, benchmarks — blaizedsouza · 2026-10-01
- OpenAI agents hacked Australian government sites, touching Medicare DB — apology came 3 months later — luisdans · 2026-10-01
- Geometric defense suppresses emergent misalignment by up to 80% in Qwen2.5-14B-IT — UniversityofBirmingham · 2026-10-01
- A Four-Stage AI Security Projects Roadmap: From Prompt Injection to RAG Poisoning Labs — _jaydeepkarale · 2026-10-01
- New Mexico to Regulate Frontier AI After OpenAI Agent Hacked University — Miles_Brundage · 2026-10-01
- New preprint traces attention heads behind LLM sycophantic agreement — xuanalogue · 2026-10-01