Cars Cars

Millions of Cars Hide a Hackable Alarm That Could Unlock, Disable and Expose Them to Theft

A device originally installed to protect vehicles from theft has left millions of cars exposed to unauthorized unlocking, tracking and immobilization. Many affected drivers may not even know the equipment is inside their vehicle.

Computer-security researchers at the University of California San Diego discovered serious vulnerabilities in a Bluetooth-enabled version of the KARR Security System. The aftermarket alarm is commonly installed by dealerships to monitor inventory and protect vehicles while they are waiting to be sold.

The researchers estimate that at least 2.2 million vehicles contain the vulnerable equipment. Their findings suggest that someone within Bluetooth range could send unauthorized commands to affected cars, including commands to unlock the doors, disable the alarm, flash the lights, sound the horn or prevent a parked vehicle from starting.

The problem is especially concerning because the device was not necessarily requested by the vehicle owner. Dealerships sometimes left the hardware connected after a customer declined to purchase the alarm service, meaning an inactive-looking accessory could continue creating a hidden attack surface.

What Is the KARR Security System?

KARR is an aftermarket vehicle-security platform sold by Acrisure Protection Group. Depending on the model and service package, the system can provide alarm controls, vehicle location information and theft-recovery support through a smartphone application.

Unlike security technology installed during vehicle manufacturing, the affected equipment was generally added later by dealerships. It was typically connected beneath the driver-side dashboard and wired into systems responsible for door locks, lights, the horn and ignition control.

The device communicates with a mobile application through Bluetooth. That connection allows an authorized user to perform functions resembling those available through a vehicle’s key fob. The system can lock or unlock the doors, activate warning signals and prevent the engine from starting when the vehicle is not already running.

The manufacturer continues to describe KARR as an anti-theft and recovery solution on its official customer website. The newly disclosed vulnerability concerns a Bluetooth-enabled model rather than every product or unit the company has ever supplied.

One Shared Key Weakened Millions of Devices

The central security failure involved the way KARR devices authenticated commands.

Instead of giving every vehicle a unique cryptographic credential, the affected systems relied on the same authentication key. Researchers found that key inside the KARR smartphone application’s code and used it to create a proof-of-concept app capable of imitating legitimate commands.

This meant that knowledge obtained from one application could potentially be used against many vehicles. It was similar to protecting millions of accounts with the same password and distributing that password within software that could be examined.

The weakness directly conflicts with a principle included in the National Highway Traffic Safety Administration’s vehicle cybersecurity guidance. NHTSA recommends that credentials obtained from one vehicle should not provide access to other vehicles. It also states that third-party connections should be authenticated and limited to the access genuinely required.

What an Attacker Could Do

The vulnerability did not provide complete remote control over a moving vehicle. The researchers did not demonstrate the ability to control steering, braking or acceleration, and the KARR flaw could not directly start a vehicle’s engine.

However, it could still create serious consequences.

An attacker within approximately five yards could identify a vulnerable device through its Bluetooth signal and send commands to unlock the doors. The same access could switch off the alarm, activate the horn or lights, or prevent a parked vehicle from starting.

The immobilization risk is the source of descriptions suggesting that the device could “paralyze” a car. The vulnerable system could stop a vehicle from starting, potentially stranding its owner, but the disclosed attack did not shut down an engine that was already running.

Unlocking a vehicle would not automatically allow a thief to drive it away. Nevertheless, UC San Diego researchers demonstrated that unauthorized entry could be combined with commercially available locksmith equipment capable of programming a working key. The KARR weakness could therefore remove the noisy and visible step of breaking a window before another theft method was attempted.

Bluetooth Signals Could Also Reveal Vehicle Locations

The risk extends beyond immediate unlocking.

The researchers found that vulnerable devices broadcast recognizable Bluetooth signals. Those signals could allow nearby scanners to identify cars carrying the affected system. Crowdsourced wireless-signal databases may also contain historical observations showing where a particular device has previously been detected.

In theory, that information could help an attacker identify where a vehicle is regularly parked. It could also allow someone to determine whether a targeted car is likely to contain the vulnerable alarm before approaching it.

Researchers estimated the scale of the problem partly by examining data collected by WiGLE, a public database of wireless-network observations. They also scanned roads around the UC San Diego campus and reportedly identified 97 KARR-equipped vehicles within 20 minutes.

This does not mean that every affected car is being actively tracked. It demonstrates that a device intended to increase security can unintentionally expose a persistent identifying signal.

Many Owners Never Agreed to Use the Device

The distribution method makes the vulnerability unusually difficult to resolve.

Dealerships installed the system to control and monitor vehicles in their inventory. When a car was sold, the customer could be offered the KARR service as a paid upgrade. Customers who accepted the package could use its mobile features, but the physical hardware often remained connected even when the offer was declined.

UC San Diego researchers found that these apparently deactivated devices could continue broadcasting and accepting Bluetooth communications. They could also be reactivated through a radio command before other functions were triggered.

The issue therefore sits outside the normal relationship between an automaker and a vehicle owner. A manufacturer recall may not reach the device because the automaker did not design or install it. A dealership may have lost contact with the owner, particularly when the vehicle has been resold.

This fragmented chain of responsibility helps explain why aftermarket vehicle cybersecurity requires greater attention. NHTSA warns that third-party equipment can act as a pathway into systems that influence physical vehicle behavior, even when the accessory’s original purpose is not safety-critical.

How Drivers Can Identify an Affected Vehicle

Affected vehicles appear to be especially common in Southern California, where dealerships have installed the systems since approximately 2017. Researchers reported finding them in vehicles sold by dealerships representing Honda, Toyota, Mazda, Ford and Jeep, although the vulnerability is tied to the aftermarket alarm rather than to those automakers. Used-vehicle sales have also distributed affected cars across the United States and into other countries.

A KARR or SWDS sticker on the driver-side window may indicate that the equipment was installed. SWDS refers to SouthWest Dealer Services, an Acrisure subsidiary associated with the system.

Another sign is a small button or blinking light mounted beneath the dashboard on the driver’s side. However, owners should not disconnect unfamiliar wiring without professional guidance. An incorrectly removed alarm or immobilizer can interfere with the ignition, locks or other electrical systems.

A driver who finds one of these signs can contact the dealership that sold the car or KARR customer support to confirm the device type and determine whether it requires an update.

A Firmware Patch Is Available

Acrisure released a firmware update on July 20, 2026, one day before UC San Diego publicly announced the findings. The company characterized the real-world risk as low but said it developed the update to address the researchers’ concerns.

Owners who already use the KARR Security smartphone app should receive an update notification. According to instructions reported alongside the research, other affected owners may need to install the KARR app, connect it to the vehicle’s alarm and use the customer-service section to start the firmware update.

The patch creates a communication challenge because many owners do not know that they have the device. Drivers should therefore verify the hardware rather than assuming that their car is unaffected because they never purchased a KARR subscription.

Cars Need Supply-Chain Cybersecurity, Not Just Manufacturer Updates

The discovery highlights a broader weakness in connected transportation. Vehicle security depends on more than the software developed by the automaker. Dealership accessories, insurance devices, diagnostic tools, fleet trackers, mobile applications and entertainment equipment can all create additional entry points.

A vehicle may receive every official manufacturer update and still remain exposed through an unpatched third-party component. Effective protection therefore requires unique credentials, restricted system access, secure update mechanisms and a reliable process for notifying every owner throughout the vehicle’s life.

The KARR case is particularly striking because an anti-theft device appears to have made unauthorized entry easier. Its lesson reaches far beyond one alarm company: any accessory connected to a vehicle’s critical functions must be treated as part of the vehicle’s cybersecurity system, even when it is hidden beneath the dashboard.

Leave a Reply

Your email address will not be published. Required fields are marked *