Critical KARR Bluetooth Flaw Exposes 2.2M Vehicles to Remote Unlock Attacks
A critical Bluetooth vulnerability in the dealer-installed KARR Security System exposes more than 2.2 million vehicles across the United States to remote unlocking, immobilization, and horn/light manipulation attacks by anyone within Bluetooth range.
Researchers at the University of California San Diego disclosed the flaw after discovering that the aftermarket alarm, commonly installed by dealerships including Honda, Toyota, Mazda, Ford, and Jeep lots across Southern California between 2017 and 2026, relies on a shared authentication key hardcoded into the official KARR smartphone app.
The vulnerability stems from a universal Bluetooth authentication key that researchers extracted while reverse-engineering the KARR app’s communications protocol.
Critical KARR Bluetooth Flaw
This design flaw resembles classic Bluetooth impersonation attacks against trusted peripherals, where a device fails to verify the identity of a connecting client beyond a static shared secret.
Because the key is identical across all affected devices rather than unique per vehicle, the UCSD team built a proof-of-concept Android application that impersonated legitimate KARR software and successfully transmitted unauthorized commands to nearby alarm units.
Using the PoC, lead researcher Andrew demonstrated the ability to unlock vehicles, disable alarms, sound horns, flash lights, and immobilize parked vehicles from starting. Notably, the flaw does not permit remote engine start or control of a moving vehicle, limiting the attack to stationary targets.
Deactivated units remain exposed even after purchase: when a buyer declines the paid KARR subscription, the hardware stays wired into the vehicle and continues broadcasting and accepting Bluetooth signals while the engine runs, and for up to 10 minutes afterward.
UC San Diego used the crowdsourced wireless-signal database WiGLE to estimate deployment at over 2.2 million Bluetooth-enabled KARR units nationwide. During a single 20-minute drive near campus using a standard Android phone, researchers detected signals from 97 KARR-equipped vehicles.
This persistent broadcast behavior creates a secondary privacy risk: historical WiGLE records could potentially reveal a targeted vehicle’s frequent locations over time.
Acrisure Protection Group, which markets KARR, released a firmware patch on July 20, 2026, roughly 18 months after initial disclosure. A company spokesperson characterized the attack as “highly complex” with “low risk under real-world conditions,” while confirming remediation through the KARR app, website, and dealer communications.
Neither UCSD nor Wired found evidence of in-the-wild exploitation. However, the universal key significantly lowers attack complexity, since a single technique compromises every affected device rather than requiring vehicle-specific exploitation.
Detection and Mitigation
Roughly half of affected owners never requested or knowingly received the KARR hardware, making detection critical:
- Check driver-side window for KARR or SWDS (SouthWest Dealer Services) branding
- Inspect underneath the dashboard for a blinking-light module
- Download the KARR Security app (iOS/Android) if not already installed
- Connect the app to the vehicle, select customer service, then apply the firmware update
- Contact the selling dealership or KARR support if hardware cannot be identified
Andrew notes that installing the app and applying the patch remains the primary mitigation, though owners must first manually confirm the hardware’s presence in their vehicle before remediation can begin.
No Comment! Be the first one.