A hidden aftermarket security device installed in millions of vehicles could allow an attacker standing nearby to unlock the doors without breaking a window or stealing the owner’s key.
Cybersecurity researchers at the University of California San Diego discovered the vulnerability in certain KARR and SWDS anti-theft systems commonly fitted by car dealerships. The affected device communicates through Bluetooth and is connected to functions including the door locks, horn, headlights and engine immobiliser.
UC San Diego estimates that at least 2.2 million vehicles contain vulnerable equipment. The most serious complication is that many drivers may not realise the device is installed, particularly when they declined to purchase the dealership’s optional security service or bought the car second-hand.
Acrisure Protection Group, the company behind KARR Security, released a firmware update on July 20, 2026. However, the fix must reach each affected device, including systems whose owners have never activated the associated app.
The Vulnerability Is Not in the Car’s Factory Key
The problem does not originate in a vehicle manufacturer’s standard key fob, infotainment software or factory-installed alarm. It concerns a third-party module added by participating dealerships.
Dealers install KARR systems to monitor vehicles, manage inventory and discourage theft while cars remain on their lots. The equipment is normally positioned beneath the dashboard on the driver’s side and wired into systems that control several security functions.
When the vehicle is sold, the dealership may offer access to the hardware and smartphone app as a paid upgrade. Buyers who accept the service can use their phones to lock or unlock the car, activate the horn, flash the lights and access other supported security functions.
The unusual risk appears when a customer rejects the upgrade. According to the UC San Diego investigation, the hardware may remain installed and active even though the owner never paid for, configured or used it.
That means a driver may be responsible for updating a connected security product that was neither requested nor knowingly activated.
One Shared Authentication Key Created the Problem
Bluetooth itself is not automatically insecure. A properly designed system authenticates each authorised user and ensures that credentials from one device cannot be used to control another.
Researchers found that the affected KARR-SWDS systems relied on the same authentication key. After reverse-engineering the smartphone application and extracting that credential, they were able to reproduce the communication process in a proof-of-concept Android app.
The researchers compared the design to giving an entire product line the same unchangeable password. Instead of one stolen credential affecting one vehicle, the shared key potentially provided access to every vulnerable unit using that authentication system.
This design directly conflicts with modern automotive cybersecurity principles. The National Highway Traffic Safety Administration’s cybersecurity guidance states that credentials obtained from one vehicle should not provide access to other vehicles. It also recommends strong authentication and limited permissions for third-party devices connected to vehicle systems.
What an Attacker Could Do
The attack requires the person to be physically nearby rather than operating from anywhere in the world. UC San Diego’s tests found that access was possible from approximately five yards away, although Bluetooth range can vary according to the environment, hardware and interference.
From that distance, the researchers demonstrated that their app could silently lock or unlock doors, disable the alarm, flash the headlights and sound the horn. The same vulnerability could prevent a parked vehicle from starting when its engine was already off.
The exploit does not directly start the engine. Someone cannot simply approach with a phone, unlock the car and immediately drive away using only the Bluetooth vulnerability.
However, gaining quiet access to the interior removes an important barrier. The researchers showed that once inside, an attacker could use commercially available locksmith equipment to create a working key on certain vehicles. Such tools have legitimate professional uses, but they may also be misused after unauthorised access has been obtained.
The vulnerability could also be used for disruption rather than theft. Preventing a vehicle from starting could leave its owner stranded at home, at work or in a public car park.
Which Cars May Be Affected?
The issue is associated with the installed security module, not one specific make or model.
Most of the identified vehicles were originally sold through Honda, Toyota, Mazda, Ford and Jeep dealerships in Southern California from 2017 onwards. Because cars are resold and moved between regions, researchers also detected affected vehicles throughout the United States, in Canada and as far away as Japan.
This does not mean that every vehicle produced by those manufacturers is vulnerable. A car is at risk only when it contains the affected KARR or SWDS hardware and has not received the corrected firmware.
KARR Security told Popular Science that the research affected a small percentage of its devices containing certain Bluetooth-related components. The company also said it had not seen evidence that the vulnerability had been exploited in real-world vehicle break-ins and described the practical risk as low because of the technical knowledge required.
The researchers nevertheless consider the potential impact serious because the vulnerable equipment was widely deployed and many owners may not know they have it.
How Drivers Can Check Their Vehicles
One visible sign is a sticker containing the word “KARR” or “SWDS” on the driver’s-side window. SWDS refers to Southwest Dealer Services, a name associated with some installations.
Drivers may also find a small blinking button or indicator beneath the dashboard on the driver’s side. The component may be positioned around the lower dash area near the steering column or footwell.
A missing sticker does not guarantee that the device is absent. Stickers can be removed, while a previous owner may have received little or no documentation about dealership-installed equipment.
Owners who are uncertain can contact the original selling dealership or KARR customer support and provide the vehicle identification number. This may be particularly important for used vehicles purchased without complete service and accessory records.
The hardware should not be pulled out or disconnected without professional assistance. Because it may be integrated with the ignition, locks and vehicle electronics, incorrect removal could create electrical problems or prevent the car from starting.
How to Install the Security Update
KARR has published official firmware-update instructions for both activated and non-activated systems.
An existing customer can sit in the vehicle, open the KARR Security app, select the connected car and navigate to the settings area. The Check for Updates option will confirm whether new firmware is available and guide the user through installation.
A person who never activated the system can still download the app and use KARR’s customer-service option to verify the device through the vehicle identification number. The company says non-active systems can then receive the update even when the security subscription was never purchased.
The update should be completed while the user is close to the car because the phone must communicate with the module through Bluetooth. KARR lists its customer-support number as 800-395-5277 for owners who cannot identify the device or complete the process.
Why Reaching Every Owner Will Be Difficult
Updating a known customer who regularly uses the KARR app is relatively straightforward. The company can display an alert and direct that person toward the new firmware.
The harder problem involves drivers who rejected the service, never created an account or purchased the vehicle from a later owner. They may not appear in KARR’s active customer records and may have no reason to visit its website.
A manufacturer recall normally benefits from vehicle-registration records, dealer networks and established owner-notification procedures. This vulnerability involves equipment installed later in the supply chain, making it harder for the original car manufacturer to identify every affected vehicle or deliver the fix through an ordinary factory software update.
Acrisure said it intended to notify users through the KARR app, its website and dealership communications. The effectiveness of that effort will depend on whether dealers can identify both original and subsequent owners.
The Flaw Reveals a Wider Connected-Car Risk
Modern cars contain factory electronics, mobile applications and communication systems, but their cybersecurity exposure does not end with the manufacturer.
Dealer alarms, fleet trackers, insurance dongles, diagnostic tools and aftermarket entertainment systems can all connect to sensitive vehicle functions. A weakness in any one of those products may create an unexpected route into the wider car.
NHTSA warns that an aftermarket device can influence safety-related vehicle behaviour when it is not properly protected. Its guidance specifically calls for strong authentication, limited access and secure credentials for third-party products connected through Bluetooth, Wi-Fi, USB or diagnostic interfaces.
The KARR vulnerability is particularly concerning because the product was designed to prevent theft. Instead, a shared digital credential turned it into a possible method of silently entering a vehicle.
Drivers do not need to panic, and there is currently no confirmed evidence that thieves have widely used this specific flaw. Owners should still check for the hardware and install the update promptly. A vulnerability becomes far less useful once the affected device has received the corrected firmware.