BYD Australia answered points made on ABC’s Four Corners program about the cybersecurity of its Shark 6 ute.
The highly biased television report focused exclusively on Chinese-built electric vehicles. That targeted focus plays straight into a classic “reds under the bed” scare. It completely ignored non-Chinese ICE and electric cars. In reality, automotive cybersecurity and OTA update protection have been core engineering priorities across the world’s car industry ever since OTAs first became available. Modern software-defined vehicles come from every country that manufactures vehicles, and all face these architecture challenges.
Gartner predicted in 2022 that 70% of new vehicles will run Android Automotive by 2028. That shift marks an industry migration from legacy, proprietary platforms to one based on Android.
ABOVE: Shark 6
Automakers are increasingly using Android Open Source Project (AOSP) software to reduce the development costs of their digital infrastructure. They claim it streamlined software development, and allows deployment of OTA updates more efficiently.
Many brands now use Android Automotive OS (AAOS). Legacy brands like Volvo, Ford, Nissan, Renault, Honda, and General Motors (including Chevrolet, Cadillac, and GMC) utilise this native operating system to power their infotainment systems. Meanwhile, Stellantis (parent company of Jeep, Dodge, and Chrysler), premium German manufacturers like BMW and Audi, EV innovators like Rivian and Lucid, and Turkish automaker Togg are using this architecture for their next-generation software platforms.
A large portion of the 70% projection will be Chinese EV manufacturers and tech conglomerates, including BYD, Leapmotor, Geely (along with Zeekr and Lotus), Nio, Xiaomi, and Xpeng, who use Android Open Source Project (AOSP) to power their own branded connected vehicle ecosystems.
None of these are to be confused with Android Auto or Apple CarPlay which a merely phone mirroring apps that project your phone onto the infotainment screen.
BYD took the claims seriously. Australian and Chinese technical teams launched an immediate joint forensic probe.
The ABC used engineers who focused on 2 specific attack vectors raised in their broadcast. The first involved the vehicle’s infotainment system and the Android Debug Bridge. ADB is a standard Android command-line developer tool, not proprietary BYD software. It remains turned off by default in production cars and requires special tools for access.
Researchers exploited a software bug to force ADB on and install an untrusted third-party app.
BYD engineers successfully reproduced this flaw during testing. Crucially, the system still enforced standard user permission barriers. When the rogue app requested access to cabin microphones or GPS location, the touchscreen displayed clear prompts. An occupant had to manually approve those requests before any data could be read. This is something a normal person wouldn’t do.
The second area centred on direct physical access to the vehicle’s internal CAN bus network.
BYD’s forensic analysis confirmed that taking control of headlights and windscreen wipers required physically tapping straight into the vehicle wiring harness. This attack requires hands-on physical tampering on a target vehicle. According to BYD, it can’t be done remotely, and it only affects the single car that was physically spliced.
Without cutting into wires, any external device wanting network access must plug into the On-Board Diagnostics port. BYD’s OBD has physical isolation and device authentication engineered to international UN R155 cybersecurity standards.
Action is already underway with BYD already completing a root-cause investigation into the ADB bug and then building a software fix.
The fix removes the unintended user-interface pathway that allowed ADB activation. Once the validation wraps up, BYD will push the fix out to Shark 6 vehicles as an OTA update. Engineers are also checking if other BYD models in Australia require the patch.
Meanwhile, a dedicated risk assessment is looking at whether the internal CAN network needs extra checks on the messages it carries. BYD will also use the findings to tighten its security testing across the range.
As the ABC didn’t source non-Chinese models, the problem might well be industry-wide. Either way, it’s unlikely an owner would miss a screen prompt asking for microphone access, or someone cutting into the wiring.
BYD was right to reply, but highly biased reporting will continue as legacy brands become more and more desperate to remain viable. Instead of picking the most popular car in the country, Tesla Model Y, or Toyota’s Rav4 at number 2, both of which have external access and OBD ports, the ABC chose 3 Chinese Cars that challenge both Tesla and Toyota.
More BYD Stories
- Mixed BYD Sealion 5 ANCAP result breaks five-star run
- Australia’s Cheapest New Car Is the $19,990 BYD ATTO 1
- 2026 BYD ATTO 3 EVO Premium Goes Rear-Drive at $46,990

Leave a Reply