CarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Notification
  • Autonomous Driving
  • Automotive Ethernet
  • BMS
  • ECU
  • EV
  • ISO/SAE 21434
  • Infotainment
  • OTA Updates
  • OBD-II
  • Pwn2Own
  • RCE
  • SDVs
  • TCU
  • UNECE R155
Cybersecurity

St. Paul pulls plate reader cameras after data reached immigration agents

Policy & Compliance

China freezes vehicle software to end patch-later OTA era

Policy & Compliance

NRMA and Lexus Australia push Canberra toward car data law

Policy & Compliance

Quebec report declares car data consent fundamentally broken

Font ResizerAa
CarThreatCarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
Search
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Sign In Sign In
Follow US
© 2026 Carthreat.com. All right reserved.
Cybersecurity

Dealer-installed alarm exposes 2 million cars to Bluetooth theft attacks

A hidden alarm device in over 2 million cars lets attackers unlock doors and kill engines over Bluetooth, and most owners do not even know it is there.

CarThreat Staff
Last updated: July 21, 2026 9:39 pm
By
ctadmin
2 Min Read
SHARE

UC San Diego researchers have revealed that more than 2 million vehicles across the United States carry a hidden aftermarket alarm system with a Bluetooth vulnerability allowing anyone within range to unlock doors, disable the ignition, and track the car’s location.

The flaw resides in the KARR Security System, a Bluetooth-connected device installed by car dealerships primarily in Southern California since 2017 to manage inventory and prevent lot theft. The device, marketed as a paid upgrade through a smartphone app, remains active in vehicles even when the buyer declines the feature. Buyers often never know it is there.

Researchers found that every KARR device shares the same hardcoded cryptographic key. Cracking that single key unlocked access to all 2 million units. An attacker within Bluetooth range can silently unlock the car without any authentication, or immobilize the engine by sending radio commands through the device’s direct connection to ignition and door-lock wiring.

The research team, led by Professor Aaron Schulman, notified Acrisure Protection Group about the vulnerability in January 2025. The company released a firmware patch on July 20, 2026, that car owners must install manually through the KARR Security smartphone app. Owners who never downloaded the app or who do not know their car has the device remain unprotected.

Affected vehicles typically carry a KARR or SWDS sticker on the driver-side window. The button for the system sits under the dashboard on the driver’s side. Honda, Toyota, Mazda, Ford, and Jeep dealerships sold the bulk of vulnerable cars, but resales have spread the risk nationwide and abroad.

Stefan Savage, a UCSD professor who co-led the first car hacking demonstration in 2010, called this probably the worst car hacking threat ever discovered because manufacturers cannot fix it and owners do not know they are at risk.

Join Our Newsletter
Subscribe to our newsletter to get our newest articles instantly!
TAGGED:Bluetooth SecurityCAN BusConnected VehiclesECU SecurityKeyless EntryVehicle SoftwareVulnerabilities
SOURCES:WiredUC San Diego TodayThe Drive
Share This Article
Facebook Email Copy Link

Follow US

Find US on Social Medias
FacebookLike
XFollow
YoutubeSubscribe

You Might Also Like

Cybersecurity

rFpro Extends AV Simulation Platform With Cabin Monitoring Support

By
ctadmin
June 12, 2026
Policy & Compliance

Connected vehicle security act clears Senate committee hurdle

By
ctadmin
July 22, 2026
Cybersecurity

Volkswagen Golf EV Delayed Again as SSP Software Platform Stalls

By
ctadmin
May 26, 2026
Policy & Compliance

Quebec report declares car data consent fundamentally broken

By
ctadmin
August 23, 2026
Snapdragon Digital Chassis concept illustration of an electric vehicle with glowing internal components
Cybersecurity

Stellantis Pushes Hands-Free Driving With Qualcomm Snapdragon Ride Pilot

By
ctadmin
May 25, 2026
Cybersecurity

NHTSA tells self-driving car makers to stop blocking ambulances

By
ctadmin
July 12, 2026

CarThreat

Intelligence for the EV and automotive security market
  • News
  • Features
  • Spotlight
  • Events
  • About Carthreat
  • Our Mission
  • Services
  • Contact Us
  • OBD-II
  • Automotive Ethernet
  • TCU
  • Infotainment Systems
  • SDVs
  • BMS
  • ECU Security
  • CAN Bus
  • Vulnerabilities
  • Relay Attacks
  • RCE
  • Threat Intelligence
  • Cybersecurity
  • Digital Keys
  • Bluetooth Security
  • OTA Updates
  • ISO/SAE 21434
  • UNECE R155
  • Regulations
  • Data Privacy
  • EVs
  • Autonomous Driving
  • Pwn2Own Automotive

© 2026 Carthreat.com. All right reserved.  Privacy Policy | Legal

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?