BYD Australia says an over-the-air update for the Shark 6 will remove the route that, by BYD's account, a Canberra security firm used to switch on the ute's Android Debug Bridge, the developer interface that let it plant the remote-control software shown on the ABC's Four Corners last month. The clearest explanation of what that means for owners came from a third party. All Terrain, an Australian accessory company whose EVX app is installed on the Shark's center screen through that same interface, told its owners group it expects the method to stop working once the update lands, and it has paused development of the app.Those two outcomes come from one decision, and the decision belongs to BYD. On a software-defined truck, the manufacturer controls what code may run on the dashboard, and a single download can shut out a researcher's exploit and an owner's chosen accessory at once. What the update leaves alone is the access the researchers were hired to imitate in the first place: BYD's own.How the Four Corners demonstration was builtFour Corners aired its investigation, Asleep at the Wheel, on Sept. 21. In the ABC's written account, reporter Angus Grigg drives a Shark 6 outside Canberra while Dan Hreszczuk, co-founder of Fortify Labs, locks the doors, runs the wipers at full speed, cuts the headlights, follows the truck on a map and turns on the cabin microphone. Hreszczuk told the ABC the access he used "didn't even have a password." The Auto Wire covered the initial findings and how the roadside demonstration worked.On Sept. 27, Fortify Labs published its own account of the work. The firm said its assignment was to "Simulate the remote access a car manufacturer has to a connected vehicle and demonstrate how this access could be abused," and that getting into the truck in the first place was never the point. The test vehicle was a 2025 Shark 6 Premium the firm owned, reported fully patched as of July 16, 2026, with head-unit software version 56.1.2.2507080.1.Fortify said it used a publicly known technique to get low-level access to the head unit, which required being physically in the vehicle, and installed software that did most of what viewers saw. From then on, the control worked remotely. Before starting, the team pulled the SIM card out of the truck's telematics box and gave the Shark internet access through its own cellular hotspot, so nothing in the test touched BYD's servers. The headlight and wiper tricks came from a separate step: a Raspberry Pi spliced into the CAN bus wiring, standing in for a compromised control module.The firm also credited BYD. It wrote that the head unit's SELinux policies, together with the separation provided by a QNX hypervisor, kept it away from the cameras and other sensitive parts of the vehicle. It has withheld the entry technique, saying it is easy to reproduce, works on other Android-based head units that aren't locked down, and would give stalkers and abusers a way to switch on a car's microphone or track it live.The Shark 6's center screen runs an Android-based infotainment system. The Android Debug Bridge route into it is what BYD says its update will close. Photo: Ethan Llamas via Wikimedia Commons, CC BY-SA 4.0What BYD says the update will changeI could not find BYD Australia's statement on the company's Australian website. The most detailed public summary I found came from All Terrain, which relayed it to its Shark and Denza owners group. By that account, BYD said the update will remove an unintended pathway that let ADB be enabled through the infotainment system. BYD also said it will tighten debug-interface management, app permission controls, pre-release security testing and vulnerability management. Separately, it has begun a risk assessment of the CAN bus covering message authenticity, integrity and freshness. I found no public release date for the update.The fix comes at a moment when BYD has a lot of trucks and cars to protect. The ABC reported the company is on track to sell about 100,000 vehicles in Australia this year, almost double its 2025 total.Why closing ADB also shuts out an accessory makerAndroid Debug Bridge is the command-line tool developers use to connect a computer to an Android device, install apps from outside an app store and run shell commands on it. On a phone, it hides behind a developer menu and an on-screen prompt asking whether to trust the connected computer. On a car's head unit, it separates the apps the manufacturer approved from everything else.Third-party developers like it for the same reason attackers do. All Terrain's EVX app puts live vehicle data and tilt, pitch and roll displays on the Shark's screen, and its installation depends on sideloading through ADB. In its owners-group post, All Terrain said it is pausing the app's roadmap, will keep developing its EVX VCU hardware, and can't yet say whether BYD's CAN bus changes will affect how that hardware talks to the truck. The company summed up the risk of building on someone else's platform: "BYD ultimately controls the infotainment software and vehicle architecture and can change how third-party software or hardware is able to interact with the vehicle."Closing the hole is the correct engineering call. It also means Shark owners who sideloaded apps onto their trucks can expect to lose them as a side effect of a security update they didn't ask for and can't negotiate.CAN bus authentication is hard to add after the truck is builtThe headlight demonstration points to an older problem than Android. The Controller Area Network, which Bosch introduced in 1986, is a broadcast system. Every module on a segment hears every message, and a message is labeled by what it is, not by who sent it. A lighting module that receives a "lights off" frame cannot tell whether it came from the body controller or a Raspberry Pi tapped into the harness behind a kick panel.The three words in BYD's risk assessment describe the standard fix. Authenticity and integrity mean attaching a short cryptographic code to each message, generated with a key the sender and receiver share, so a forged or altered frame fails the check. Freshness means adding a counter or timestamp so a message recorded today can't be replayed tomorrow. The automotive software standard AUTOSAR calls this Secure Onboard Communication. It needs keys provisioned in every participating module, spare room in each message and processing headroom in each controller, which is why carmakers usually design it into a platform rather than add it by download. BYD has committed to an assessment, not to a change, and it has not said whether any change would reach trucks already on the road.For owners, authenticated CAN messages would cut both ways. An attacker with a splice and a cheap computer would get a lot less out of it. So would any accessory installer whose product listens to, or talks on, the same messages. Making those products work again would take the automaker's cooperation.The access the update leaves in placeFortify's stated goal was to show what a manufacturer's remote reach could do in the wrong hands. That reach is real and legitimate: automakers can contact their vehicles over the telematics connection, run commands and push software. The Shark 6 fix will arrive through that channel. In its write-up, Fortify described a ransomware scenario in which criminals who break into a carmaker's back-end systems push a malicious update to every connected vehicle of one brand, leaving each one needing a technician to reflash its modules by hand. Oslo's transit agency raised a similar question when it tested a Chinese-built electric bus inside a mountain to find out what its manufacturer could reach remotely.Data handling is the other half. The ABC reported that BYD's Australian privacy policy had listed China among 16 countries where Australians' data could be sent and referred to collecting data through "surveillance activities." Two days after Four Corners asked about it, BYD said the policy had been reviewed and updated. The new version, with no mention of China or surveillance, was uploaded one hour and 16 minutes before BYD sent it to the program. It still allows overseas transfers under applicable law. BYD told the ABC: "We haven't and would not transfer any data of Australians to the Chinese authorities." The company also said it had responded to preliminary inquiries from Australia's privacy regulator. The head-unit update does not touch the privacy policy or where the data goes.Australia has no car cybersecurity rule; Britain and the U.S. went different waysThe ABC reported that Australia has no minimum cybersecurity standard for cars, so nothing compelled BYD to keep the Shark's software current or run a formal system for managing cyber risk. Tony Burke, the minister for Home Affairs and Cyber Security, told the program the government had started with household connected devices. Fortify points to draft Australian Design Rules 115 and 116, modeled on United Nations Regulations 155 and 156, which cover how manufacturers manage cybersecurity and deliver software updates. The firm wants the final rules to go further and govern where the back-end systems that manage Australian vehicles are hosted and who can get into them.Britain is already under those UN rules. According to its Vehicle Certification Agency, R155, which requires a cybersecurity management system, has applied to existing vehicle type approvals since July 7, 2024. The United States took a different route. BYD doesn't sell passenger vehicles here, though it builds buses in California, and the Commerce Department's connected-vehicle rule, published Jan. 16, 2025, bars connected-vehicle software tied to China or Russia starting with the 2027 model year and covered hardware starting with 2030. That keeps certain suppliers out. It sets no security standard for the cars that are allowed in, and NHTSA's cybersecurity best practices describe themselves as non-binding and voluntary.What Shark 6 owners should look for in the updateRead the release notes when the update appears on the screen. They should say whether the ADB route is closed and whether BYD offers any approved way to install third-party apps. Watch for the result of the CAN bus assessment and whether any change applies to trucks already sold or only to new builds. If you run aftermarket electronics that connect to the truck's wiring or screen, ask the installer what happens to them after the update. Fortify's main advice to owners is to install head-unit updates when prompted rather than dismissing them, and to ask the mechanic at each service to confirm all software updates have been applied.If your truck's maker can switch off an app you chose in the same update that closes a security hole, should owners get a say in what runs on their dashboard, or is that the price of a safer truck?⚡ Read the full article on The Auto Wire