UC San Diego researchers have revealed that more than 2 million vehicles across the United States carry a hidden aftermarket alarm system with a Bluetooth vulnerability allowing anyone within range to unlock doors, disable the ignition, and track the car’s location.
The flaw resides in the KARR Security System, a Bluetooth-connected device installed by car dealerships primarily in Southern California since 2017 to manage inventory and prevent lot theft. The device, marketed as a paid upgrade through a smartphone app, remains active in vehicles even when the buyer declines the feature. Buyers often never know it is there.
Researchers found that every KARR device shares the same hardcoded cryptographic key. Cracking that single key unlocked access to all 2 million units. An attacker within Bluetooth range can silently unlock the car without any authentication, or immobilize the engine by sending radio commands through the device’s direct connection to ignition and door-lock wiring.
The research team, led by Professor Aaron Schulman, notified Acrisure Protection Group about the vulnerability in January 2025. The company released a firmware patch on July 20, 2026, that car owners must install manually through the KARR Security smartphone app. Owners who never downloaded the app or who do not know their car has the device remain unprotected.
Affected vehicles typically carry a KARR or SWDS sticker on the driver-side window. The button for the system sits under the dashboard on the driver’s side. Honda, Toyota, Mazda, Ford, and Jeep dealerships sold the bulk of vulnerable cars, but resales have spread the risk nationwide and abroad.
Stefan Savage, a UCSD professor who co-led the first car hacking demonstration in 2010, called this probably the worst car hacking threat ever discovered because manufacturers cannot fix it and owners do not know they are at risk.