A single shared authentication key baked into a widely deployed, dealer-installed car alarm has left more than 2.2 million vehicles across the United States exposed to attackers who never have to touch a door handle.
The system, called KARR Security, is aftermarket hardware that dealerships bolt onto vehicles on the lot, and it often stays connected even after a buyer declines to pay for the service.
KARR Bluetooth Flaw
Researchers at the University of California, San Diego found that anyone within Bluetooth range of a KARR-equipped vehicle can unlock it, disable its alarm, sound the horn, flash the lights, or stop a parked car from starting.
The flaw cannot be used to start or drive away with a vehicle remotely, but it can grant quiet cabin access that skips the noise and risk of traditional break-in methods.
UCSD professor Aaron Schulman summed up the stakes bluntly: “This is a system added to cars by dealers, and unfortunately, it has a severe vulnerability that allows anyone to gain access to any of these cars”.
“The KARR case is a reminder that supply-chain security doesn’t end at the factory gate every bolt-on device a dealer adds becomes part of the vehicle’s attack surface, whether the owner asked for it or not.”
Because KARR is third-party hardware and not part of an automaker’s factory system, the flaw sits outside the normal recall and over-the-air update channels that carmakers use.
Apple CarPlay, the iPhone-to-car connection, and Apple’s own software are unaffected; this is strictly an issue with Acrisure’s aftermarket alarm hardware.
UCSD researchers estimate that at least half of the owners with KARR installed never requested it, since dealerships routinely equipped their entire inventory and left the hardware in place after a sale, even when buyers opted out of the paid alarm feature.today.
The flaw traces back to a single authentication key shared across all Bluetooth-enabled KARR units, discovered by researchers reverse-engineering the official smartphone app.
As Malwarebytes noted, the key sits in plain text inside the app, meaning “extract it once and you can communicate with any KARR-equipped vehicle made since 2017”.
Deactivated units still broadcast and accept Bluetooth commands while the engine runs and for up to 10 minutes afterward, and researchers built a proof-of-concept Android app that unlocked cars, disabled starters, and triggered horns and lights on demand.
Beyond unauthorized access, the always-on Bluetooth broadcast lets anyone with a scanner and access to the crowdsourced WiGLE wireless database potentially map where a specific vehicle has repeatedly been detected.
During a single 20-minute drive near the UCSD campus, researchers picked up signals from 97 separate KARR-equipped vehicles using nothing more than a standard Android phone.
Mitigation
Acrisure, which sells KARR through its SouthWest Dealer Services subsidiary, released a firmware patch on July 20 after an 18-month disclosure window that began in January 2025.
The company has called the exploit “highly complex” and low-risk in real-world conditions, though the update landed just before scheduled DEF CON and USENIX presentations on the research.
Drivers can check for exposure and remediate as follows:
- Look for a “KARR” or “SWDS” sticker on the driver-side window, or a small blinking-light button under the dashboard.
- Download the KARR Security app for iPhone or Android if not already installed.
- Connect the app to the vehicle’s alarm, then select “customer service” and “firmware update”.
- Confirm any pending update notification if already using the app.
- Contact the selling dealership or KARR support directly if the hardware can’t be identified.
The episode underscores a broader lesson for connected-vehicle security: aftermarket hardware installed by intermediaries can create risk that persists long after the point of sale, and outside the reach of standard automotive patching pipelines.