Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
AndroidAuto — Open-source Android Auto phone-side implementation with protocol reverse engineering, TLS mutual authentication, H.264 video projection, touch input injection, and sensor data streaming over USB AOA. | Kitploit
Tools/GitHubGitHub/mretallack/androidauto
Android SecurityBluetooth SecurityReverse EngineeringWireless SecurityMobile SecurityPapers & ResearchLearning & Education
GitHubmretallack/androidauto

AndroidAuto

Open-source Android Auto phone-side implementation with protocol reverse engineering, TLS mutual authentication, H.264 video projection, touch input injection, and sensor data streaming over USB AOA.

View Repository
11304 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Open Android Auto

An open-source implementation of the Android Auto phone-side app. This app runs on your phone and projects to a car's head unit over USB, replacing Google's proprietary com.google.android.projection.gearhead APK.

⚠️ WORK IN PROGRESS

This project is in early development. The protocol handshake and video projection are working with a real head unit. The phone screen is successfully displayed on the car's head unit for several seconds before disconnecting (video stability is being improved).

Features

Protocol & Connection

  • USB AOA accessory mode detection and connection
  • TLS 1.2 mutual authentication (phone as server)
  • Version negotiation (protocol v1.7)
  • Service discovery (request/response)
  • Channel open on target channels (video, audio, input, sensor)
  • Ping/pong keepalive (bidirectional)
  • Audio focus request/response handling
  • Navigation focus request/response handling
  • Voice session request handling
  • Graceful shutdown handling
  • Priority write queue (control messages over video)
  • Wait for audio focus grant before sending audio (500ms timeout per HUIG)
  • Bluetooth pairing exchange (BluetoothPairingRequest/Response)
  • Handle multiple USB reconnections without AOAP re-init

Video Projection

  • H.264 encoding via MediaCodec (800x480 @ 30fps, Baseline profile)
  • MediaProjection screen capture (with user permission dialog)
  • Video channel setup (SETUP → CONFIG → FOCUS → START flow)
  • Zero-based timestamps in microseconds
  • SPS/PPS prepended to keyframes (Annex B format)
  • Flow control (max_unacked tracking, backpressure)
  • Frame pacing (consistent 33ms intervals)
  • Stable long-running video (currently disconnects after ~7 seconds)
  • Resolution negotiation from head unit's service discovery
  • Adaptive bitrate based on connection quality

Touch Input

  • Input channel open and binding request
  • Touch event parsing (single and multi-touch)
  • Key event parsing (buttons, media keys)
  • Coordinate mapping (head unit → phone resolution)
  • TouchInjector with MotionEvent creation
  • Inject touch events into VirtualDisplay
  • Key event injection into Android system

Audio

  • Audio channel open and setup
  • Wait for audio focus grant before sending audio (500ms timeout per HUIG)
  • Send AUDIO_FOCUS RELEASE on initial connect, then GAIN when playing
  • Phone audio capture (MediaProjection AudioPlaybackCapture)
  • PCM/AAC encoding and streaming to head unit
  • Microphone input from head unit (voice commands)
  • Multiple audio channels (media, system, speech, guidance)
  • Audio silence streaming to keep channel active

Sensors

  • Sensor channel open
  • Sensor start request/response handling
  • Night mode data parsing and sending
  • Driving status data parsing and sending
  • GPS location forwarding
  • Compass heading
  • Car speed
  • RPM
  • Odometer (total + trip mileage)
  • Fuel level and range
  • Parking brake state
  • Gear position (P/R/N/D/1-10)
  • OBD-II diagnostics
  • Environment (temperature, pressure, rain)
  • HVAC (target/current temperature)
  • Dead reckoning
  • Passenger presence
  • Door state (hood, boot, individual doors)
  • Light state (headlights, indicators, hazards)
  • Tire pressure
  • Accelerometer (3-axis)
  • Gyroscope (3-axis)
  • GPS satellite data
  • Respond to head unit sensor requests proactively

Video (additional)

  • Resolution negotiation from head unit's service discovery
  • Adaptive bitrate based on connection quality
  • Support for 720p, 1080p, 1440p, 4K resolutions
  • Portrait mode resolutions (720x1280, 1080x1920, etc.)
  • UI config updates (theme, insets)

Other

  • Bluetooth pairing coordination (A2DP, HFP)
  • Navigation turn-by-turn to instrument cluster
  • Navigation state (maneuvers, lanes, distances, current position)
  • Media status (now playing info)
  • Media playback metadata (track, artist, album)
  • Media browser (browse phone media library from head unit)
  • Phone status (call state notifications)
  • Generic notifications (subscribe/unsubscribe system)
  • Vendor extensions
  • Wireless Android Auto (WiFi + Bluetooth handoff)
  • Channel close notification
  • Car connected devices request/response
  • User switch request/response
  • Battery status notification
  • Call availability status
  • Service discovery update (dynamic channel changes)
  • Input feedback (haptic/visual feedback to head unit)
  • Microphone request/response (voice input from head unit)
  • Audio underflow notification
  • Radio service (AM/FM/HD/DAB tuning, presets, RDS)

⚠️ DISCLAIMER

USE AT YOUR OWN RISK. This software is provided "as is", without warranty of any kind.

  • This software may cause unexpected behaviour with your car's head unit
  • This software may damage your phone or head unit — the authors accept no liability
  • DO NOT use this application while driving
  • DO NOT interact with this application while operating a vehicle
  • This application is intended for development and testing purposes only
  • Always pull over and stop your vehicle before interacting with any phone application
  • The authors are not responsible for any accidents, injuries, or damages resulting from the use of this software

Architecture

USB Plug-in → MainActivity → ProjectionService
                                    ↓
                    UsbAoaTransport (USB AOA accessory mode)
                                    ↓
                    MessageFramer (16KB frame fragmentation)
                                    ↓
                    InBandTls (TLSv1.2 via SSLEngine)
                                    ↓
                    ProtocolEngine (AAP state machine)
                                    ↓
                    ┌───────────┼───────────┐
                 Video      Input       Audio
                (H.264)   (touch/keys)  (PCM)

Known Bugs

  • Channel assignment assumes order — We assign the first av_channel in SERVICE_DISCOVERY_RESPONSE as video and the second as audio. This works with the car head unit (channel 1 = video) but fails with openauto (channel 4 = audio, not video). Fix: parse the stream_type field inside av_channel to distinguish VIDEO(3) from AUDIO(1).
  • Video stability — Connection drops after extended streaming due to head unit USB buffer overflow. See test results below.
  • Duplicate device listing on head unit — The head unit's smartphone page shows our app as two separate entries (one for Android Auto, one for Bluetooth) instead of a single entry with both capabilities. This is caused by Android 12+ blocking access to the real Bluetooth MAC address (returns 02:00:00:00:00:00). Workaround: write the real address to a config file via adb shell "echo $(adb shell settings get secure bluetooth_address) > /sdcard/Android/data/org.openandroidauto/files/bt_address.txt". Need a UI settings screen to let the user enter their BT MAC manually.
  • Voice assistant button not handled — When the driver presses the voice/assistant button on the head unit, we receive a VOICE_SESSION_REQUEST and attempt to launch a voice assistant (Dicio or system default). However, the launched assistant doesn't receive audio from the head unit's microphone yet.

Video Stability Test Results

Test pattern (color bars) at 800x480, I-frame interval 1 second:

Download Tool