Modern cars can collect location data, connect to smartphones, and receive software updates without visiting a dealership. A cybersecurity demonstration involving a BYD Shark 6 has shown what can happen when access to some of those systems falls into the wrong hands.
Australian cybersecurity firm Fortify Labs spent weeks examining a 2025 Shark 6 Premium for an investigation aired by ABC’s Four Corners. Researchers ultimately demonstrated access to information, including the truck’s location and microphone, while also showing its headlights and windshield wipers being controlled.
As reported by CarExpert, the demonstration prompted BYD Australia to launch an internal investigation. Engineers were able to reproduce parts of the researchers’ work and identified what the automaker describes as a “software defect” involving the Shark 6’s Android-based DiLink infotainment system.
BYD is now preparing corrective software for the pickup and investigating whether other models require similar changes. There is an important caveat, however: the demonstration wasn’t a case of hackers simply finding a Shark 6 online and remotely taking control of it from scratch.
The Initial Hack Required Physical Access

According to BYD, researchers exploited a flaw that allowed Android Debug Bridge, or ADB, to be enabled through the infotainment interface. This provided a pathway to install an untrusted third-party application.
Fortify Labs confirms that physical access to its Shark 6 was necessary to install the software. Once installed, however, connectivity and control of that software could operate remotely, which allowed researchers to demonstrate access to functions including location and the microphone.
BYD also says permission prompts appeared when the application requested certain functions and had to be manually approved through the infotainment screen. The planned update will remove the unintended method of enabling ADB through that interface.
The Headlights And Wipers Were A Separate Test
The dramatic demonstration involving the Shark’s headlights and windshield wipers used another method entirely. Fortify Labs physically tapped into the truck’s CAN bus and connected a Raspberry Pi that simulated a compromised electronic control unit sending messages across the network.
BYD’s investigation similarly concluded that this portion of the test required direct physical intervention. The automaker has nevertheless started a separate risk assessment to determine whether additional protections for CAN messages are necessary and technically feasible.
Fortify Labs also disconnected the Shark’s factory telematics SIM before conducting its research. Remote connectivity was instead provided through the researchers’ own cellular hotspot and infrastructure, meaning BYD’s online services weren’t used for the demonstration.
An OTA Update Is Coming

BYD says it will release an over-the-air update for the Shark 6 once the revised software has completed validation testing. The company is also checking whether other vehicles using related software will need the same corrective action.
Fortify Labs stressed that its findings shouldn’t be viewed solely as a BYD or Chinese-vehicle problem. The researchers say inadequately secured Android-based infotainment systems from other manufacturers could potentially face similar issues.
The firm is now calling for greater scrutiny of connected-car security, including the possibility of a consumer-facing cybersecurity rating system. As vehicles become increasingly dependent on software and remote connectivity, keeping that software patched is becoming another part of car ownership — even when there isn’t anything mechanically wrong.
