#Ford #AppLink is a pretty cool protocol, even though it's officially discontinued.
Turns out, there's nothing stopping you from spoofing an arbitrary "App ID" meaning you can get the permissions of the old version of the FordPass app.
This includes making arbitrary OBD-II/UDS queries and getting live location data.
Not really a user security issue, per se, since the user still has to approve turning on AppLink and allowing access to vehicle data... but still interesting.
https://github.com/BlueOvalLabs/pyapplink
Replying to
@jjtech@infosec.exchange
You can connect to #AppLink via TCP using the car's built-in "Wireless Projection" Wi-Fi network, or via USB or Bluetooth via #iAP2.
The vehicle-side permission prompt is keyed on App ID + MAC address of the Bluetooth device connecting.
Luckily I don't think anyone has AppLink enabled nowadays, since it's not supported by any modern apps?
You've seen all posts