A security vulnerability was discovered in Subaru's STARLINK connected vehicle service, allowing unauthorized access to customer accounts and vehicle control. The vulnerability was reported and patched within 24 hours, and it was not exploited maliciously. The vulnerability allowed attackers to remotely start, stop, lock, and unlock vehicles, as well as access customer location history and personal data. The issue was found in the STARLINK admin panel, which is used by Subaru employees to manage customer accounts.