Northeastern researchers, working with Consumer Reports, found 19 of 21 vehicles reached third parties over Wi Fi.
A peer-reviewed study by a Northeastern University team, working with Consumer Reports' test fleet, found that 19 of 21 U.S.-market vehicles reached at least one third-party domain over Wi-Fi between October 2024 and August 2025. The companion mobile apps were the leakier pipe: 7 of 30 sent sensitive identifiers, including in some cases the vehicle's unique VIN, to companies associated with advertising and tracking. The team's study, pending at the Internet Measurement Conference '26, reports that pairing an app to a vehicle increased the combined system's average exposure to those companies.
The study's main contribution is methodological. Instead of treating "connected car privacy" as a single problem, the team separated the modern vehicle into two data pipes: the head unit that ships with the car, and the phone app the owner downloads to unlock remote start, climate pre-conditioning, and location features. Each pipe was measured independently.
The head unit was the louder pipe by count. Researchers captured vehicle traffic on the fleet's Wi-Fi and watched 19 of 21 cars reach out to third-party domains. The packet contents were encrypted under transport-layer security, the same protection that secures a browser session. Seeing a destination IP address is not the same as seeing what was sent. The researchers are explicit about that limit: the test shows where vehicles are talking, not what they are saying. Destination observation does not establish what personal data those vehicle connections carried.
The phone app was the leakier pipe by payload. The team installed mitmproxy, a tool that intercepts encrypted traffic for inspection, with custom root certificates on test devices, and captured the full request stream of every companion app it tested. All requested permissions were accepted during the study. Seven of those 30 apps transmitted sensitive identifiers, including names, email addresses, and in some cases the VIN, to domains associated with ad networks and data brokers. Pairing an app to a vehicle increased the combined system's average exposure to ad and tracking companies.
Adding a phone app to a car multiplied the number of third parties receiving data from the combined system. The mechanism is straightforward: an app installed under a real owner's account, with real permissions granted, will collect what its developer chose to collect. The researchers do not claim the apps caused the cars themselves to transmit more data. They measured exposure across the combined system and reported the comparison.
Two terms carry most of the load. PII, or personally identifying information, means data that can be tied to a specific person: a name, an email, or a vehicle's VIN. The VIN, the unique serial number stamped on every car, appears in some app traffic as a persistent tracking identifier. The test fleet, run with Consumer Reports, is the trust signal: real production vehicles the researchers could drive and instrument without relying on manufacturer cooperation.
The disclosure loop has already produced one concrete change. The research team reports that Honda, after being shown its findings, modified a practice that had been transmitting precise geolocation to a third party associated with tracking. That is the researchers' account, not an independently confirmed current behavior, and it is the constructive payoff of the study: a common factual footing for consumers, regulators, and manufacturers to act on.
The sample is 21 U.S.-market vehicles, not every brand or model on sale. All app permissions were accepted during testing, so the study does not measure whether denying permissions reduces exposure. Destination observation on encrypted vehicle packets is not proof of payload contents. The "first large-scale" framing is the authors' own characterization, not an independent priority claim. None of the findings establish that data was sold, shared with insurers, or used to harm a specific driver.
The team's paper publishes the methodology and the manufacturer-response record. For a reader buying a new car or signing up for a companion app in the next year, the practical question is which pipe is being asked to do more than it should: the head unit, the phone, or the permissions the owner grants on day one.