Smartphones on Wheels: How Automakers Quietly Sell Driver Geolocation to Ad Trackers

Smartphones on Wheels: How Automakers Quietly Sell Driver Geolocation to Ad Trackers

Connected VehiclesPrivacyData Security

Sources:Northeastern University / Consumer Reports

Between 2024 and 2025, researchers from Northeastern University teamed up with Consumer Reports to test 21 late-model production vehicles, drawing from a test fleet that would have cost over $1.2 million to assemble independently. Placing vehicles inside a car-sized Faraday tent to attenuate cellular signals and intercepting traffic via dedicated Wi-Fi access points, the team analyzed network activity alongside 30 companion mobile apps. The empirical results were damning: 19 of the 21 vehicles tested transmitted data to third-party advertising and tracking companies behind the driver’s back.

The real business model of the connected vehicle ecosystem is treating driver personal data as an automaker asset to monetize within programmatic advertising. In this setup, informed consent is largely an illusion: drivers are forced to choose between surrendering their privacy or losing essential vehicle functionality.

A $1.2M Probe Tears Open the Black Box

Obtaining hard empirical proof of backend vehicular telemetry is extraordinarily costly. Vehicles from the same manufacturer exhibit wildly divergent network behaviors, meaning consumers cannot deduce their privacy posture simply by looking at a badge. To establish ground truth, the research team conducted comprehensive real-world testing across 19 brands, leveraging a test fleet valued at more than $1.2 million.

Car-sized Faraday tent Figure: A vehicle-sized Faraday tent providing ≈93 dB of attenuation, used to sever cellular connectivity for 11 electric vehicles. Source: Northeastern University Automatic Transmission Study

To isolate cellular traffic and observe network destinations, researchers deployed a physical containment setup. By driving vehicles into a Faraday tent providing roughly 93 dB of attenuation, they cut off external cellular connections entirely, forcing vehicular traffic onto a custom Wi-Fi access point hosted on a Raspberry Pi. Using tcpdump to capture packets, the team observed that even when payload contents were TLS-encrypted, the destination endpoints and third-party domains were laid bare.

On mobile devices, the researchers provisioned test iPhones with custom root certificates and routed traffic through mitmproxy. After exercising the full range of features across 30 automaker companion apps, decrypted traffic unveiled an even broader surveillance web.

Companion Apps Double the Attack Surface

Automakers aggressively push companion mobile apps as essential smart conveniences, but in practice, these apps serve as wide-open front doors for third-party trackers. Out of 30 apps tested, seven directly transmitted sensitive personal identifiers to third parties associated with advertising and tracking. These data points included Vehicle Identification Numbers (VINs), email addresses, phone numbers, and precise GPS coordinates.

Connected vehicle data flow diagram Figure: Data flows in the connected vehicle ecosystem: vehicles and companion apps transmit telemetry to first- and third-party servers; solid lines indicate traffic intercepted during testing. Source: Northeastern University Automatic Transmission Study

Pairing a companion app roughly doubled a vehicle’s exposure to advertising and tracking entities on average. For a Cadillac Lyriq, the companion app added 26 new tracking domains; for a Chevrolet Blazer, 23; and for a Toyota Corolla Cross, 25. The recipients included tech conglomerates and data brokers such as Google, Meta, Microsoft, and Acxiom.

Drivers assume they are simply using an app to remotely unlock doors or precondition the climate control. In reality, the app links their real-world vehicle movements with their personal identity and feeds the bundle into ad-targeting profiles. Once data leaves the device, consumers forfeit all control over where it goes or who purchases it.

Confronted with Evidence, Automakers Shift the Blame

Armed with intercept logs, the research team initiated responsible disclosures with 17 automakers. Across the responses, one central theme emerged: shifting the blame onto the consumer.

Fourteen automakers deflected responsibility to third-party service contracts. Five claimed the observed telemetry stemmed from embedded in-app browser components. Seven explicitly asserted that consumers themselves bear responsibility for these external data destinations. The sole notable exception was Honda, which improved its data collection practices following disclosure by halting the transmission of precise geolocation to third parties associated with user tracking.

Automakers boast about software-defined intelligence on the showroom floor, yet deflect accountability to third parties and end-users the moment tracking is exposed. Carmakers have shown little appetite for taking responsibility for the tracking code running inside their vehicles.

In today’s connected vehicle ecosystem, privacy agreements do not represent genuine user choice. Owners are cornered into an unfair trilemma: blindly accept sweeping data-sharing terms, forfeit vital connected features like remote start and app control, or avoid purchasing the vehicle altogether.

This is not informed consent; it is digital extortion. When automakers tether physical hardware control to invasive data-harvesting contracts, the car ceases to be a simple mode of transportation. Every smart convenience is purchased with the digital exhaust of your daily life.

References:

  • Automatic Transmission
  • Hacker News Discussion (item?id=49926628)