Connected Vehicle Apps Leak Personal Data to Major Tech Advertising Networks

Researchers from Northeastern University and Consumer Reports discovered that vehicle manufacturer apps are transmitting sensitive driver information including vehicle identification numbers, email addresses, phone numbers and location data to third-party advertising and analytics firms. Testing of 30 apps across 21 vehicles from 19 manufacturers revealed that 19 vehicles contacted at least one third party over Wi-Fi, with 13 specifically sending data to Google-owned domains. The study highlights privacy risks in the connected vehicle ecosystem that have received little regulatory attention beyond a recent FTC enforcement action.
The research team employed a methodical approach to track data flows from connected vehicles, setting up Wi-Fi monitoring equipment and testing cars in three different operational states: stationary and inactive, stationary with active user interaction, and in motion. When standard Wi-Fi interception proved impossible due to encryption enforcement, researchers used a Faraday enclosure to block cellular signals on 11 electric vehicles, forcing them to rely on Wi-Fi instead. This technique revealed substantially more tracking domains than visible on standard connections, particularly for Tesla models, indicating manufacturers route data through multiple channels.
The companion apps accompanying vehicle manufacturer platforms compound privacy exposure significantly. Nearly three-quarters of tested apps contacted five or more advertising and analytics services, while under one-third of vehicles alone did so. Notably, several vehicles that showed no direct advertising connections when tested in isolation—including the Buick Envista and Nissan Ariya—transmitted data to 20 or more tracking companies through their associated mobile applications.
This research could affect millions of vehicle owners whose personal information flows to tech advertising networks without explicit consent or clear disclosure. Connected vehicle ecosystem vulnerabilities may expose drivers to behavioral tracking, location monitoring, and targeted marketing based on driving patterns and vehicle usage. The findings suggest current regulatory frameworks may inadequately address third-party data sharing in automotive technology, potentially influencing consumer purchasing decisions and prompting manufacturers to revisit privacy practices and app transparency disclosures.