TL;DR
Get garage and car supplies delivered free — and shop member deals
- Fast, free delivery on millions of items
- Access to Prime Big Deal Days deals on October 6–7
- Prime Video, Amazon Music and more included
A Northeastern University team working with Consumer Reports tested 21 late-model vehicles and 30 companion apps in the U.S. between October 2024 and August 2025. Researchers found that 19 vehicles contacted at least one third-party domain over Wi-Fi, while seven apps sent sensitive identifiers to third-party companies; the study says encrypted vehicle traffic limited what researchers could inspect.
A Northeastern University research team, working with Consumer Reports, reports that 19 of 21 tested vehicles contacted at least one third-party domain over Wi-Fi, while seven of 30 companion apps transmitted sensitive identifiers to third-party companies. The study measures network connections in a U.S. test sample and adds evidence about how data may move through connected-car systems, though it does not establish what every recipient did with the information.
The team tested 21 late-model vehicles spanning 19 brands and 30 manufacturer companion apps at a Consumer Reports testing facility. Experiments ran from October 2024 through August 2025. Consumer Reports provided access to its purchased vehicle fleet, which the researchers said would have cost more than $1.2 million to assemble independently.
For vehicle tests, researchers recorded Wi-Fi network traffic using a custom access point built with a Raspberry Pi. They ran stationary idle tests, active tests involving available vehicle functions, and driving tests at speeds of 5 to 45 mph, including acceleration and hard braking. The team could identify network destinations, but says vehicle traffic was encrypted, preventing inspection of the information inside those packets.
The app tests used three iPhone models and several iOS versions. Researchers installed and exercised each app, including functions such as locating a vehicle and searching for nearby charging stations, and captured app traffic using custom root certificates and mitmproxy. The report says five of 30 apps sent vehicle identification numbers alongside other personally identifiable information to trackers. It separately reports that seven apps sent sensitive identifiers to third parties.
Where Connected-Car Data Travels
The findings matter because a vehicle’s data connections can extend beyond the automaker and the driver’s phone. Network contacts with third-party domains show that outside services may be part of the connected-car ecosystem, while the app results identify instances in which sensitive identifiers were transmitted to third-party companies.
Location and vehicle identifiers can be sensitive when linked to a person or account. The report says that after data leaves a device, consumers may have limited control over how receiving companies use it or whether it is shared onward. The study documents traffic destinations and certain app transmissions; it does not, by itself, prove that every third party sold or misused data. Its value is in providing a measured look at activity that can be difficult for car owners to see.
vehicle Wi-Fi privacy protection device
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
How Researchers Measured Car Traffic
The project focuses on two points where researchers could observe data flows: vehicles themselves and their manufacturer-provided mobile apps. The team asked what personal data was transmitted, who received it and how manufacturers responded to the findings. Its report describes the work as an early effort to address limited visibility into the connected-vehicle ecosystem.
Researchers also tested a subset of 11 electric vehicles inside a car-sized Faraday tent, which the report says attenuated external cellular signals by about 93 decibels. They repeated stationary tests to investigate whether traffic that would normally use cellular service shifted to Wi-Fi when cellular communication was blocked. The report’s headline counts are specific to the tested vehicles, apps, methods and period; they should not be read as a measure of every car on the road.
The researchers partnered with Consumer Reports, which provided access to the vehicles. The report says the related paper is peer reviewed and is scheduled for publication at IMC ’26. The study page describes the wider connected-car ecosystem as including manufacturers, mobile apps and outside companies, such as advertisers and trackers.
“19/21 vehicles tested send traffic to at least one third party.”
— Northeastern University research team
As an affiliate, we earn on qualifying purchases.
Limits of the Traffic Findings
The researchers could see where vehicle Wi-Fi traffic was going, but said encryption prevented them from reading the contents of those vehicle packets. The reported contact with a third-party domain does not, on its own, reveal exactly what data was sent, how a recipient used it, or whether it was shared with other companies.
The study’s app findings are tied to the specific vehicles, accounts, phones, software versions and actions tested. The report summary does not provide a complete breakdown of the seven apps, each identifier involved, or the identity and practices of every receiving company. It also describes a manufacturer disclosure process but does not give details of each company’s response in the supplied material. The findings therefore do not establish how common the observed practices are across all models or current software versions.
As an affiliate, we earn on qualifying purchases.
Paper and Manufacturer Responses
The researchers say the peer-reviewed paper is scheduled for IMC ’26, where the methods and findings are expected to be presented in fuller detail. The report also says the team went through a lengthy disclosure process with manufacturers; the available summary does not specify the responses or any resulting changes.
Further detail about the individual domains, app transmissions and manufacturer replies would help readers understand the scope of the findings and whether practices have changed. Owners concerned about a particular vehicle can review the manufacturer’s privacy disclosures and app permissions, but the study does not provide a model-by-model guide or a universal setting that stops all data sharing.
As an affiliate, we earn on qualifying purchases.
Key Questions
How many vehicles and apps did the researchers test?
The team tested 21 late-model vehicles from 19 brands and 30 companion apps at a Consumer Reports facility between October 2024 and August 2025.
What did the study find about third-party data flows?
The report says 19 of 21 vehicles contacted at least one third-party domain over Wi-Fi. It also found that seven of 30 apps sent sensitive identifiers to third-party companies, and five sent VINs with other personally identifiable information to trackers.
Does the study show that car companies sold the data?
No. The report documents network contacts and app transmissions, but the supplied findings do not establish that automakers or recipients sold or misused data. Researchers say encrypted vehicle traffic limited their ability to inspect its contents.
When will the research paper be published?
The study website says the peer-reviewed paper is scheduled for publication at IMC ’26. The supplied material does not state a specific publication date.
Source: hn
Halloween Picks
halloween
As an affiliate, we earn on qualifying purchases.
