TL;DR
Get garage and car supplies delivered free — and shop member deals
- Fast, free delivery on millions of items
- Access to Prime Big Deal Days deals on October 6–7
- Prime Video, Amazon Music and more included
A Northeastern University research team, working with Consumer Reports, examined 21 late-model vehicles and 30 companion apps in tests conducted from October 2024 to August 2025. The team reports that 19 vehicles contacted at least one third party over Wi-Fi, while seven apps transmitted sensitive identifiers to third-party companies. The findings show data flows researchers could observe in a controlled test, but do not establish how recipients used the information.
A Northeastern University study conducted with Consumer Reports found that 19 of 21 tested vehicles contacted at least one third-party domain over Wi-Fi, while seven of 30 companion apps sent sensitive identifiers to third-party companies. The researchers say the results document data flows in the connected-vehicle ecosystem, where cars and apps can communicate with manufacturers and outside services.
The project, titled Automatic Transmission, examined 21 late-model vehicles representing 19 brands and 30 manufacturer companion apps. Testing took place in a controlled setting between October 2024 and August 2025, with apps paired to vehicles at a Consumer Reports testing facility. Consumer Reports provided access to its purchased test fleet, which the research team says would have cost more than $1.2 million to assemble independently.
For vehicle tests, researchers recorded network destinations contacted over Wi-Fi during idle, active-use and driving scenarios. They also placed 11 electric vehicles in a Faraday tent to block cellular signals and repeated some tests to study whether traffic shifted to Wi-Fi. The team says it could identify destinations in vehicle Wi-Fi traffic, but the contents were encrypted and could not be read through that method.
For app tests, researchers used iPhones, installed apps one at a time, accepted requested permissions and exercised available features. The report says seven of 30 apps sent personally identifying information to trackers; five sent a vehicle identification number together with other personal information. Those are the study’s reported observations, not proof of how receiving companies later used or shared the data.
What Vehicle Data Flows Reveal
The findings matter because a connected vehicle can generate information through its internet connection, location services and companion app, while drivers may have limited visibility into which services receive that data. The researchers describe cars and apps contacting both manufacturers and third-party domains, including advertisers and trackers. That creates potential privacy concerns around identifiers and vehicle-related information moving beyond the service a driver expects to use.
The study measures network connections and, for app traffic, information visible through its testing setup. It does not establish that every third-party contact involved advertising, that a recipient sold the information, or that a particular driver experienced harm. The results instead provide evidence for scrutiny of what data is transmitted and to whom, and raise questions about transparency, consent and the handling of information after it reaches a recipient.
automatic transmission temperature gauge kit
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
How the Connected-Car Tests Worked
The study focuses on a system with two main observation points: the vehicle itself and its manufacturer’s mobile app. Cars can use Wi-Fi or cellular connections, while apps may access functions such as vehicle location and charging information. The team’s report presents the work as a large-scale measurement of this ecosystem, rather than a review of every vehicle model or every service operating in the market.
Vehicle traffic was captured through a custom Wi-Fi access point built with a Raspberry Pi. The researchers recorded packet destinations but say encryption prevented them from reading the contents. For app traffic, they used test phones and a traffic-interception tool, with a custom certificate to inspect and decrypt network communications. These different methods affect what the researchers could observe, so the reported results should be read within the scope of the experiments.
The project was conducted in partnership with Consumer Reports, which supplied the vehicle fleet and testing access. The research website says the paper is peer reviewed and is listed for publication at IMC ’26. The study also describes a manufacturer disclosure process, though the available summary does not detail each company’s response.
As an affiliate, we earn on qualifying purchases.
What the Tests Cannot Establish
The reported counts do not show how third parties used the data, whether they retained it, or whether they passed it to additional recipients. The research team says it conducted a disclosure process and sought insight into manufacturers’ views, but the available summary does not identify company responses or explain how those responses affected the analysis.
The vehicle testing had a specific technical limit: Wi-Fi packet destinations were visible, while vehicle packet contents remained encrypted. The results also cover a sample of 21 vehicles and 30 apps tested under controlled conditions, not every connected vehicle, software version or use pattern. The summary does not provide a full model-by-model breakdown, nor does it establish whether the observed activity occurs in the same way during ordinary use by every driver.
As an affiliate, we earn on qualifying purchases.
Publication and Further Scrutiny
The research website lists the paper as peer reviewed and scheduled for publication at IMC ’26. The study team says its work is an initial step toward improving visibility into information shared by vehicles and companion apps. Readers can expect further detail in the paper about experimental methods and findings, while the manufacturer disclosure process may clarify how companies addressed the researchers’ observations.
Until those details are available, the central confirmed point remains the study’s measured network activity in its test sample. Broader conclusions about industry practices, individual companies’ data handling or consumer remedies require additional evidence beyond the counts reported on the project website.
connected car privacy protection device
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Key Questions
How many vehicles and apps did the study test?
The Northeastern University team tested 21 late-model vehicles from 19 brands and 30 companion apps. The work was carried out with access to Consumer Reports’ test fleet.
What did researchers find about third-party connections?
The team reports that 19 of 21 vehicles contacted at least one third party over Wi-Fi. This is a count from the tested sample, not a measure of how common the behavior is across all vehicles.
What information did the apps send?
The report says seven apps sent personally identifying information to trackers. Five of the 30 apps sent a vehicle identification number along with other personal information.
Does the study show that companies sold or misused the data?
No. The reported tests identify observed transmissions and recipients’ network domains. They do not establish what recipients did with the information after receiving it.
When will the full paper be available?
The project website says the peer-reviewed paper is listed for publication at IMC ’26. The source summary does not give an exact publication date.
Source: hn
Fall Picks
fall essentials
As an affiliate, we earn on qualifying purchases.
