A Survey of Critical Cybersecurity Risks in Electric Vehicle Mobile Applications: Vulnerabilities, Permissions, and Mitigation Strategies
preprint
OA: closed
Abstract
As the world accelerates toward a sustainable future with electric vehicles (EVs), smartphone applications have become an indispensable tool for drivers. These applications, developed by both EV manufacturers and third-party developers, offer functionalities such as remote vehicle control, charging station location, and route planning. However, they also have access to sensitive information, making them potential targets for cyber threats. This paper presents a comprehensive survey of cybersecurity vulnerabilities, weaknesses, and permissions in these applications. We categorize the applications into two groups: those developed by EV manufacturers and those by third parties, and conduct a comparative analysis of their functionalities by performing static and dynamic analysis. Our findings reveal major security flaws such as poor authentication, broken encryption, and insecure communication, among others. The paper also discusses the implications of these vulnerabilities and the risks they pose to users. Furthermore, we performed an analysis of requested permissions and identified functionalities that are not present in official EV applications, leading users to rely on poorly built third-party applications, thereby increasing their attack surface. To address these issues, we propose defensive measures to enhance the security of these applications, ensuring a safe and secure transition to EVs.
My notes (saved in your browser only)
Citation neighborhood (no data yet)
We don't have any in-corpus citations linked to this paper yet. This is a recent paper (2025) — citers typically take a year or two to land, and the OpenAlex reference graph may still be filling in.
Source provenance
- europepmc
- last seen: 2026-05-20T01:45:00.602351+00:00