Critical Bluetooth Flaw Exposes 2.2M Cars to Remote Attacks
Key Takeaways A critical Bluetooth vulnerability impacts approximately 2.2 million vehicles equipped with the KARR Security System. The flaw allows attackers within Bluetooth range to remotely unlock...
Key Takeaways
- A critical Bluetooth vulnerability impacts approximately 2.2 million vehicles equipped with the KARR Security System.
- The flaw allows attackers within Bluetooth range to remotely unlock doors, control alarms, and immobilize vehicles due to a shared authentication key.
- The KARR system is a dealer-installed aftermarket product, complicating traditional manufacturer-led patching efforts.
- A firmware patch was released on July 20, but vehicle owners must manually update through the KARR mobile app.
Widespread Bluetooth Flaw Exposes 2.2 Million Vehicles to Remote Attacks
A significant Bluetooth vulnerability discovered in the aftermarket KARR Security System has exposed an estimated 2.2 million vehicles to potential remote exploitation. This flaw could enable unauthorized individuals to unlock car doors, manipulate alarm functions, and even prevent engine starts, posing a substantial risk to vehicle security.
Table Of Content
The issue, brought to light by researchers at the University of California, San Diego, underscores a growing cybersecurity challenge posed by third-party hardware installed by dealerships. These systems often operate outside the robust security frameworks typically employed by automotive manufacturers, creating unforeseen vulnerabilities.
The KARR system is frequently installed by dealerships on their inventory for security purposes prior to sale. A critical aspect of the problem is that this hardware often remains in vehicles even after purchase, regardless of whether the buyer activates or pays for the service. This practice has led to a vast population of affected vehicles, many of which continue to broadcast vulnerable Bluetooth signals without their owners’ knowledge.
Understanding the KARR Bluetooth Vulnerability
Researchers detailed that the vulnerability permits an attacker within Bluetooth proximity to transmit commands directly to the vehicle’s alarm system. These commands are comprehensive, including the ability to lock or unlock doors, disarm the alarm, activate lights and horns, and prevent the vehicle’s engine from starting. While the flaw does not allow for remote driving or control of a moving vehicle, it drastically simplifies the process of car theft by enabling silent and unauthorized access to the vehicle’s interior.
The core of this vulnerability stems from a universal authentication key embedded across all KARR devices. Researchers successfully reverse-engineered the official KARR mobile application to extract this shared key. Leveraging this discovery, they developed a proof-of-concept Android application capable of impersonating legitimate KARR users. Their demonstrations successfully exploited multiple vehicles without requiring unique, device-specific exploits.
Despite the Acrisure Protection Group characterizing the KARR attack as complex and low-risk, the researchers assert that once the universal key is known, the attack becomes straightforward and highly scalable across all affected systems. This contradicts the vendor’s assessment of complexity.
Mitigation efforts are complicated because the KARR system is an aftermarket addition, not integrated into the vehicle manufacturer’s native systems. Consequently, standard over-the-air updates or manufacturer recalls are not applicable. According to an AppleInsider report, Acrisure released a firmware patch on July 20, following responsible disclosure in January 2025. However, vehicle owners bear the responsibility of identifying if their car has KARR hardware and then manually applying the update via the KARR mobile application.
Beyond the immediate risk of active exploitation, the vulnerability also raises significant privacy concerns. The KARR system continuously emits identifiable Bluetooth signals while the vehicle is in operation and for a brief period after it is shut down. Researchers utilized the WiGLE wireless tracking database to estimate the extensive deployment of these systems. They demonstrated how historical signal data could potentially be used to reveal vehicle movement patterns or frequently visited locations, highlighting an overlooked aspect of privacy risk.
During a short drive near San Diego, researchers detected signals from nearly 100 KARR-equipped vehicles, underscoring the widespread nature of these aftermarket systems and their potential to introduce substantial security vulnerabilities across millions of vehicles. This incident highlights a broader challenge in automotive cybersecurity, where third-party hardware can circumvent established security controls, leaving both manufacturers and consumers with limited visibility and delayed response capabilities.
What You Should Do
- Check for KARR Hardware: Look for KARR or SWDS branding, commonly found on driver’s side windows or underneath the dashboard.
- Download the KARR Security App: If you identify KARR hardware, download the official KARR Security mobile application.
- Apply the Latest Firmware Update: Use the KARR app to check for and install the most recent firmware patch released on July 20.
- Contact Dealership or KARR Support: If you are unable to confirm the presence of the system or complete the update, contact your dealership or KARR support for assistance.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.