Hoplon InfoSec Logo

Hoplon Infosec · Threat Intelligence

KARR Security System Bluetooth Vulnerability: Beware

BySharfunnahar Radia
Published23 Jul, 2026
KARR Security System Bluetooth Vulnerability: Beware
Sharfunnahar Radia23 Jul, 2026

Somewhere under your dashboard, right now, there might be a little black box you never asked for and never agreed to pay for. That is the strange part of this story. A team at UC San Diego just showed that the KARR Security System, an aftermarket alarm bolted into more than 2.2 million cars by dealerships across the country, can be unlocked, silenced, and disabled by a stranger standing a few feet away. No broken glass. No screaming alarm. Just a phone.

The reason is almost embarrassingly simple once you hear it. Every KARR device on the road shares the same secret key. Crack it once, and you have effectively cracked the lock on millions of cars you have never even seen.

CategoryDetail
VulnerabilityOne shared Bluetooth authentication key used across every KARR or SWDS aftermarket alarm device
Vehicles affectedAt least 2.2 million, mostly Honda, Toyota, Mazda, Ford, and Jeep models sold through Southern California dealerships since 2017
Discovered byAaron Schulman's research group at the University of California San Diego
ManufacturerAcrisure Protection Group
Attack rangeAround 5 yards according to UC San Diego, with some outlets citing up to 30 meters under favorable conditions
DisclosedJanuary 2025
PatchedJuly 20, 2026
CVE statusNo CVE identifier has been publicly confirmed for this flaw. Treat any CVE number attached to this story as unverified until a national vulnerability database entry appears

What KARR Actually is

KARR, sometimes badged SWDS, is a small Bluetooth module dealerships install under the driver side dashboard before a car ever reaches the lot. Lot managers use it to lock, unlock, or immobilize inventory from an app. Later, sales staff often pitch it to buyers as a paid convenience feature, an anti theft add on with a nice pitch about controlling your car from your phone.

What most buyers never hear is that saying no does not really turn it off. The hardware usually stays wired in and keeps broadcasting its Bluetooth signal whether you activated the service or not. Researchers estimate that around half of the owners driving a vulnerable car never asked for the device in the first place. It just came with the vehicle, like a stowaway.

This is exactly the blind spot that shows up again and again in embedded and IoT security work. Nobody remembers installing the thing, so nobody remembers to patch it either.

How the Bluetooth Flaw Works

Every KARR and SWDS unit relies on one key. Not a unique key per car, not a rotating key, just one static secret baked into both the firmware and the official mobile app. Once you have it, you have it for the whole fleet.

The UC San Diego team got that key by pulling apart the KARR Android app, a fairly ordinary reverse engineering job for anyone who knows what to look for. From there they built a small proof of concept app that could pose as a trusted KARR user and talk to any nearby device, no pairing required, no need to target one specific car ahead of time.

With that tool running, someone within Bluetooth range can quietly unlock or lock the doors, kill the factory alarm, sound the horn, flash the lights, or stop a parked engine from starting. It cannot drive your car away or take control of it while it is moving, so this is not a carjacking tool in the traditional sense. What it removes is the noise. Break ins usually announce themselves with a shattered window or a blaring alarm. This one does not, and that missing warning sign is the real danger.

One more detail worth knowing. The module keeps its Bluetooth radio on for about ten minutes after the car shuts off, so the window of exposure does not end the moment you park.

KARR Security System Bluetooth Vulnerability (2)_compressed



The Attack, From Scan to Entry

An attacker does not need custom hardware for any of this, just off the shelf radio equipment or a modified phone app to scan for KARR beacons nearby. Once a device answers, the attacker checks it against the shared universal key pulled from the official app.

From there the proof of concept software authenticates as a trusted user, without ever pairing to that particular car, and starts issuing commands. Unlock the doors. Kill the alarm. Immobilize the engine if it is parked. Then simply walk up and get in, no glass on the ground, no alarm going off, nothing to make a passerby look twice.

A Drive Through San Diego Told the Real Story

The researchers did not stop at a lab bench demo. They drove around San Diego for a short stretch and logged Bluetooth signals from nearly 100 KARR equipped cars along the way, which says a lot about how common these units already are in ordinary neighborhoods and parking lots.

Then they took the privacy angle a step further by cross referencing what they found against WiGLE, the crowdsourced wireless mapping database that hobbyists have built for years just by driving around and logging nearby signals. Because a KARR module broadcasts a persistent, identifiable signal, old WiGLE records could plausibly be used to piece together where a specific car has been parked over time. An anti theft accessory doubling as an accidental tracking beacon is not the kind of feature anyone signed up for.

Stefan Savage, a UC San Diego professor with a long history in automotive security research, called this one of the worst car hacking threats documented so far, mostly because of the sheer number of vehicles it touches and how little most owners know about the box sitting under their own dashboard.

Why Nobody Fixed This Sooner

Part of the reason this drags on so differently from a normal automaker recall comes down to ownership. Honda, Toyota, Ford, Mazda, and Jeep did not build KARR. Dealerships did the installing, protecting inventory first and selling the convenience later. Because the flaw lives entirely in third party hardware, none of those automakers can push a fix through their usual over the air update channels. The problem sits outside their world completely.

That leaves Acrisure Protection Group holding a strange responsibility, reaching millions of end users it has never directly spoken to. Plenty of owners do not know the device exists, never registered it, and have no reason to check a manufacturer recall page since this was never part of the car's original build.

Cars are increasingly just another category of connected asset falling outside a single vendor's patch cycle, which is a problem enterprise security teams already know well from attack surface management work on unmanaged devices.

How the Timeline Played Out

DateEvent
2018UC San Diego researchers stumble onto unfamiliar Bluetooth fingerprints while hunting for credit card skimmers, which eventually leads them to KARR and similar devices
January 2025Researchers privately disclose the vulnerability to Acrisure Protection Group
July 20, 2026Acrisure releases a firmware update fixing the shared key flaw, distributed through the KARR app
July 21, 2026UC San Diego publishes its research summary confirming the patch is live
August 9, 2026Researchers present full technical findings at DEF CON in Las Vegas
August 12, 2026Researchers present the peer reviewed paper at USENIX Security in Baltimore

Eighteen months passed between that first private warning and a public patch. Acrisure has described the real world risk as low and the exploit as highly complex, but that is the vendor's own characterization to reporters, not something an outside body has independently confirmed. Read it as a company defending its product, not as a settled fact.

What This Means for Business

Fleet operators, dealership groups, and insurers should care about this well beyond one alarm brand. It previews what happens when a connected accessory ships with a single shared credential instead of something unique per unit. Dealerships that installed KARR devices may end up fielding uncomfortable questions about disclosure and liability.

Insurers covering affected makes and model years may want to revisit theft risk assumptions, since silent entry breaks the usual signals a stolen car claim relies on. Fleet and rental operators running large numbers of Southern California sourced vehicles should specifically check for KARR or SWDS hardware. Even automakers face some reputational fallout here, despite never having built or shipped the flawed component themselves.

There is also a resale wrinkle worth watching. Because so many of these vehicles end up on the used market, the exposed population stretches well past the original dealership footprint. A buyer in another state, or another country entirely, could be driving a vulnerable car with zero idea a KARR module is even there.

What About Other Devices Like This One

UC San Diego also looked at Rockledge, a similar vehicle security and insurance company making comparable Bluetooth hardware. Rockledge devices seem to require an attacker to be physically present during a legitimate connection in order to record and later replay it, a harder attack to pull off than KARR's shared key problem, though not one that can be dismissed. Rockledge had not responded to the disclosure as of the researchers' publication, so its current patch status is unverified and should not be assumed safe either way.

KARR Security System Bluetooth Vulnerability


How to Fix It

The fix exists, and for most owners it does not require a trip back to the dealership. Start by checking your driver side window and the underside of your dashboard for a KARR or SWDS sticker, or a small module with a blinking light. Download the official KARR Security System app for iOS or Android and pair it with your car over Bluetooth. Inside the app, open the customer service menu and select firmware update. Once it finishes, keep the app installed so future patches reach the device automatically instead of sitting there unapplied.

If the app will not detect your module, or you want the device disabled right away for peace of mind, do not start cutting wires yourself. The unit sits close to ignition and alarm circuits, and an amateur removal can create a fire risk or leave the car's electrical system in an unpredictable state. A qualified auto electrician, or the dealership that installed it, can safely disconnect the dedicated fuse as a stopgap while you sort out the firmware update properly.

On the legal side, removing or disabling third party hardware like this generally does not touch your original manufacturer warranty, since KARR was never part of the factory build. Still, keep a record of when and how you removed it, and check your specific dealership sale agreement, since some financing or protection packages quietly bundle the device into the contract.

Hoplon Insight Box

Treat every aftermarket embedded device the way you would treat an unmanaged endpoint on a corporate network. Inventory it, check its patch level, and never take a vendor's low risk label at face value without independent testing behind it. Fleets should fold connected vehicle accessories into an existing vulnerability management program rather than leaving individual drivers to track it on their own.

Frequently Asked Questions

Can someone actually drive away with my car using this flaw?
No. It allows unlocking, alarm control, and immobilization while the car is parked, but not remote driving or control of a moving vehicle.

My dealer never mentioned a KARR subscription. Am I still at risk?
Yes. The hardware often stays active and broadcasting even when an owner never activated or paid for the service.

How do I check if my car has this device?
Look for a KARR or SWDS sticker on the driver side window, or a small module with a blinking light mounted under the dashboard near the driver's seat.

The app will not detect my module. What do I do for an emergency fix?
Contact a qualified technician about disconnecting the dedicated fuse rather than attempting removal yourself, since the wiring sits close to ignition and alarm circuits.

Why hasn't my car manufacturer issued a recall?
KARR is dealer installed aftermarket hardware, not part of the original manufacturer's build, so it sits outside normal factory recall and over the air update channels.

Does removing the device void my warranty?
Generally no, since it is third party equipment, but check your dealership sale or financing agreement for any bundled protection package language.

Hoplon Technical Takeaway

Strip away the headlines and this comes down to one design decision. KARR shipped with a single shared secret instead of a unique credential per device, and that one choice turned 2.2 million individually sold cars into one giant, connected attack surface. Now the fix depends on owners who mostly do not know the hardware exists finding an app they never downloaded.

Any business evaluating a connected accessory, whether it rides in a vehicle fleet or sits on an office network, should ask the vendor directly how authentication keys get provisioned and whether each unit carries its own unique credential. If the answer is vague, treat the device as unmanaged until proven otherwise.

Teams that need a structured way to surface this kind of gap across a large hardware footprint can start with a gap assessment, or bring in virtual CISO services to build real ownership into the patching process before the next aftermarket flaw makes headlines.

Fleet and dealership groups specifically can pair that review with cyber resilience assessment work to close the gap between discovering a problem and actually fixing it. Hoplon InfoSec works with organizations on exactly this kind of embedded device exposure, so reach out if your fleet, product line, or office needs a real audit instead of a vendor's word that the risk is low.

If you want a broader primer on locking down the phones now controlling everything from car alarms to home security, Hoplon's guide on how to protect your phone from hackers is worth a read. Teams building or auditing companion apps like the KARR mobile client will also find practical steps in the mobile application security best practices guide.

Was this useful?

React, leave a note, or share it forward.

Leave a note

Share this article

Share this :

03Latest posts

Free · Weekly · No noise

Get the threats that matter, before they reach you.

One short email a week with the breaches, zero-days, and fixes worth your attention — written in plain English, no fear-mongering.