
The BYD Shark 6 is another reminder that vehicle cybersecurity is becoming as important as automotive safety. The issue emerged in Australia after Fortify Labs researchers examined a Shark 6 and demonstrated infotainment vulnerabilities. Their work was featured by ABC’s Four Corners, prompting BYD Australia to investigate the matter.
Importantly, this was not a case of researchers sitting remotely and taking control of an unsuspecting pickup. Fortify Labs said physical access to the vehicle was initially needed to install software on its infotainment system. After that initial compromise, however, the researchers demonstrated that the affected system could communicate remotely.
The researchers also demonstrated access to the vehicle’s CAN bus, the internal network through which electronic control units communicate. Using a Raspberry Pi to simulate a compromised electronic control unit, they showed how messages could be sent to affect functions including the headlights and windscreen wipers.
BYD subsequently identified what it described as a software defect involving Android Debug Bridge, or ADB. According to the automaker’s investigation, the vulnerability created an unintended way for ADB to be enabled through the infotainment interface and for an untrusted application to be installed.

The company says it identified a corrective action and is preparing an over-the-air software update for the Shark 6. BYD says the update will be released after the revised software has completed validation. It is also assessing whether other models require similar action.
There is an important limitation to the demonstration. BYD said access to the headlights and windscreen wipers required direct physical access to the vehicle’s CAN wiring. The research therefore does not establish that an attacker could simply target a Shark 6 over the internet and immediately control those functions.
That distinction is worth emphasizing because vehicle-hacking stories can sometimes make an attack sound considerably easier than it actually is. Nevertheless, the underlying cybersecurity concern remains. Vehicles today rely heavily on connected infotainment, wireless communications, smartphone integration, over-the-air updates and electronic networks linking multiple control modules. Those features improve convenience, but they also create additional software that must be protected throughout a vehicle’s life.
The bigger lesson extends beyond BYD. Fortify Labs noted that similar cybersecurity risks can potentially affect vehicles from any manufacturer using inadequately secured connected or Android-based systems. As vehicles become increasingly software-defined, cybersecurity will have to become a continuing part of vehicle development, maintenance and ownership. The Shark 6 case shows why this matters.

Autocar’s Take
The BYD Shark 6 cybersecurity story is a useful reminder that the definition of vehicle safety is changing rapidly. Cars are no longer purely mechanical products; they now also depend on software, connected services and electronic networks that can introduce another category of risk.
However, the details matter. Calling this simply a remote vehicle takeover would leave out an important part of the research. Physical access was required at the beginning of the demonstrated attack, while the researchers’ access to functions such as the headlights and windscreen wipers also involved the vehicle’s CAN wiring.
That does not make the vulnerability irrelevant. If anything, it shows why connected-car security needs to be considered in layers, from infotainment systems to the networks connecting a vehicle’s electronic control units. BYD’s investigation and planned software update are therefore welcome steps.





