Jeep Cherokee, Infiniti Q50 and Cadillac Escalade named most hackable US cars
Security researchers identified the 2014 Jeep Cherokee, 2014 Infiniti Q50 and 2015 Cadillac Escalade as the most vulnerable to hacking in a study of 20 vehicles.
Three mainstream US-market vehicles, the 2014 Jeep Cherokee, 2014 Infiniti Q50 and 2015 Cadillac Escalade, were identified as the most hackable cars in a cybersecurity study released in August 2014. The findings came from Charlie Miller and Chris Valasek, researchers known for their work on automotive security, who reviewed 20 models for their susceptibility to remote attacks.

Miller, a security engineer at Twitter, and Valasek, director of vehicle security research at IOActive, published their results ahead of the Black Hat conference in Las Vegas. Their report did not involve direct hacking of the vehicles. Instead, the pair analysed publicly available technical documentation and assessed the attack surfaces, such as wireless connectivity, Bluetooth, telematics and network architecture, of each model. The aim was to benchmark the relative risk for consumers and the industry, rather than to exploit any specific vulnerabilities.
How the vehicles were assessed
The researchers ranked the 2014 Jeep Cherokee, 2014 Infiniti Q50 and 2015 Cadillac Escalade at the top of their risk list. All three models combine extensive wireless features with network architectures that, according to the study, could allow remote access to critical vehicle controls. The report highlighted that a high number of connectivity features and less isolated internal networks raise the risk of a successful attack.

- 2014 Jeep Cherokee: Exposed to remote access risk via its Uconnect infotainment system.
- 2014 Infiniti Q50: Multiple wireless entry points and network integration.
- 2015 Cadillac Escalade: Telematics and infotainment systems linked to vehicle controls.
The study did not attempt to exploit or demonstrate live hacks on these vehicles. Miller and Valasek emphasised that their rankings offer a comparative measure, not a definitive statement on real-world security. A model with a large attack surface could still be well-protected if its software is robust, while a car with fewer features might have overlooked vulnerabilities.
Industry response and implications for buyers
Chrysler, Nissan and General Motors, the manufacturers of the three named models, responded to the report by stating they would review the findings and, if necessary, address any security concerns. Chrysler said it would verify the claims and remediate them if warranted. The report’s authors stressed that their work was intended to provide a benchmark for buyers considering connected cars, not to single out manufacturers for negligence.
The study’s publication coincided with growing concern among US consumers about car hacking risks. A related survey reported that 80 percent of respondents expected car hacking to become a frequent problem in the near future. As more vehicles adopt connected features, cybersecurity is moving up the agenda for manufacturers and buyers alike. For a broader look at public attitudes to car hacking, seeMost Consumers Expect Car Hacking to Become Routine Threat.
