Car Car

A Hidden Car Alarm Flaw Could Let Hackers Track, Unlock and Disable 2.2 Million Vehicles

A security system intended to prevent vehicle theft may have exposed at least 2.2 million cars to unauthorised unlocking, location tracking and ignition disruption.

Researchers at the University of California San Diego discovered a serious vulnerability in certain KARR and SWDS aftermarket security devices installed by dealerships. The affected hardware communicates through Bluetooth and may remain connected to a vehicle even when the buyer declined to purchase or activate the alarm service.

That installation practice creates the most troubling part of the discovery. Many affected drivers may not know that the device exists, making it unlikely that they would search for or install its security update.

Acrisure Protection Group, which sells the KARR system, released a firmware patch on July 20, 2026. However, owners must identify the device and update it manually through the KARR application. Vehicles that remain unpatched could continue accepting unauthorised Bluetooth commands from someone standing nearby.

The Vulnerability Is Inside a Dealer-Installed Alarm

The flaw does not originate in the vehicle manufacturer’s original key, factory alarm or infotainment system. It affects an aftermarket device that dealerships commonly install before a vehicle is sold.

Dealers use these systems to monitor inventory and discourage theft while cars remain on their lots. The device is normally wired beneath the dashboard on the driver’s side and connected to systems controlling door locks, the horn, headlights and ignition immobilisation.

After the sale, a dealership may offer the alarm and accompanying mobile application as a paid security upgrade. When the customer refuses the service, the physical hardware may still remain wired into the vehicle.

UC San Diego researchers found that the inactive device could continue broadcasting and receiving Bluetooth signals. In certain situations, an attacker could activate the dormant system and issue commands even though the vehicle owner had never subscribed to it. The university’s official explanation of the KARR vulnerability says many affected installations date from 2017 onwards.

One Shared Key Put Every Device at Risk

A secure wireless system should uniquely authenticate each device and authorised user. Compromising one customer’s credentials should not automatically compromise every other customer.

The researchers found that the affected KARR devices instead relied on the same authentication key. That key was also present within the code of the KARR smartphone application.

Once the research team extracted and understood the shared key, it created a proof-of-concept application capable of generating commands accepted by nearby vulnerable devices. The design was comparable to giving every alarm the same permanent password and embedding that password inside publicly distributed software.

The flaw was especially serious because owners could not independently change the key. Anyone who successfully reproduced the authentication process could potentially communicate with any vulnerable KARR device within Bluetooth range.

The researchers have deliberately withheld detailed replication instructions while coordinating disclosure with the vendor, relevant manufacturers and the National Highway Traffic Safety Administration. Their academic work, titled BLE Theft Auto: Evaluating the Security of Aftermarket BLE-Based Automotive Remote Control Systems, is scheduled for presentation at major cybersecurity conferences.

Hackers Could Unlock or Immobilise a Nearby Car

The attack is not described as a global internet-based exploit that allows someone in another country to control a vehicle. The attacker generally needs to be within Bluetooth range, which researchers measured at approximately five yards under their test conditions.

From that distance, an unauthorised device could lock or unlock doors, disable the alarm, sound the horn or flash the headlights. It could also prevent a parked vehicle from starting, potentially leaving its driver stranded.

The flaw does not directly allow an attacker to start the engine. However, silently unlocking the door removes a major obstacle for a thief. Researchers demonstrated that commercially available locksmith equipment could then be connected inside some vehicles to create a working key and drive the car away.

Without the Bluetooth exploit, a thief might need to break a window, manipulate the physical door or trigger the alarm. The vulnerable security device could instead provide quieter access before the second stage of the theft begins.

The Tracking Risk Does Not Require Access to GPS

Reports that the cars can be “tracked” need an important clarification. The researchers did not claim that the shared Bluetooth key automatically gives an attacker access to a live satellite map of every affected car.

The privacy risk comes partly from the Bluetooth identifier repeatedly broadcast by the installed device. Crowdsourced radio databases such as WiGLE collect the approximate locations where Bluetooth and Wi-Fi signals have been detected.

By searching for a particular device identifier, someone could potentially view historical locations associated with that KARR unit. This information might reveal where a vehicle is frequently parked, such as near a home, workplace or regularly visited destination.

Researchers used these radio records to estimate how widely the devices had been deployed. The same information could potentially help an attacker identify a vehicle’s routine locations and choose an opportunity for theft or sabotage.

That distinction still represents a serious privacy concern. Continuous real-time GPS access is not required when historical radio sightings can reveal predictable movement patterns.

Which Vehicles May Have the Vulnerable Device?

UC San Diego estimates that at least 2.2 million cars may contain affected hardware. Most were originally sold through Honda, Toyota, Mazda, Ford and Jeep dealerships in Southern California from 2017 onwards.

The issue is not limited to those manufacturers or to California. KARR is a dealer-installed product rather than a factory system tied to one vehicle brand. Used-car sales have also carried equipped vehicles into other parts of the United States, Canada and locations as distant as Japan.

A vehicle may be affected when it has a KARR or SWDS sticker on the driver’s-side window. Another sign is a small button or blinking light mounted beneath the dashboard near the driver’s side.

The absence of an obvious sticker does not conclusively prove that no system is installed. Stickers may be removed, and used-car owners may not receive the original dealership documentation.

Owners who purchased vehicles from participating dealerships during the affected period may need to contact the selling dealer or KARR support for confirmation. The KARR Security website provides access to its customer application and support information.

The Patch Must Be Installed Manually

Acrisure released firmware intended to address the vulnerability on July 20, 2026. Drivers who already use the KARR application should receive information about the available update.

Owners without the application may need to download it, connect to the security system and locate the firmware-update option through the customer-service section. Because many owners never activated or purchased the system, they may not receive an automatic notification through the app.

This creates a difficult patching problem. The car manufacturer cannot necessarily fix a third-party dealership device through an ordinary vehicle software update. A dealership may also have difficulty contacting the current owner when the vehicle has changed hands several times.

Acrisure told WIRED that the vulnerability was complex and represented a low risk under real-world conditions, but it nevertheless developed a firmware update. UC San Diego’s researchers have urged owners to install that update promptly.

Removing the Hardware Is Not a Simple Alternative

Physically removing the system may sound more reliable than installing new software, but researchers warned against treating it as a simple unplug-and-discard accessory.

The device can be deeply integrated with the vehicle’s wiring, computer systems and ignition controls. Incorrect removal could prevent the car from starting, damage electrical components or interfere with legitimate factory systems.

An owner who wants the hardware removed should therefore use a qualified dealership or automotive electrical technician familiar with KARR installations. Cutting wires or disconnecting an unidentified module without understanding the installation could create additional safety and reliability problems.

The safer immediate response is to confirm whether the device exists and apply the vendor’s firmware update.

The Incident Exposes a Larger Automotive Security Problem

Modern vehicle cybersecurity involves more than software developed by major car manufacturers. Dealership alarms, insurance trackers, fleet-management units, diagnostic dongles and entertainment accessories can all create additional routes into sensitive vehicle systems.

NHTSA’s automotive cybersecurity guidance defines the field broadly, covering electronic systems, communication networks, software and underlying data. Its best-practice recommendations also call for rapid vulnerability remediation and greater attention to aftermarket components.

The KARR discovery shows why that broader view matters. A car may receive every official manufacturer update and still remain vulnerable because of hardware added elsewhere in the sales chain.

The affected device was sold as a defence against theft, yet one reusable authentication key turned it into a potential entry point for thieves. Until the patch reaches the millions of vehicles that may contain it, awareness remains the greatest challenge particularly for owners who never knew the system was installed.

Leave a Reply

Your email address will not be published. Required fields are marked *