Tue 21 Jul 2026 / 11:44 ET
Kernel
Internet 3 min read

KARR car alarm flaw lets nearby hackers unlock and disable vehicles

UC San Diego researchers say a dealer-installed KARR alarm used in millions of vehicles can be abused over Bluetooth unless owners install new firmware.

Dana Voss

By Dana Voss / Security Correspondent

KARR car alarm flaw lets nearby hackers unlock and disable vehicles
img: WIRED

Acrisure Protection Group has released new firmware for a Bluetooth-enabled KARR aftermarket car alarm after UC San Diego researchers found a flaw that could let a nearby attacker unlock vehicles, silence alarms, trigger horns and lights, or stop a car from starting.

The awkward part for drivers is the supply chain. According to the UCSD team, dealers often install KARR Security System units on cars to protect inventory on lots, then leave the hardware in place after sale, including when buyers do not pay to activate the feature. UCSD estimates more than 2 million vehicles have the affected Bluetooth model installed, many of them driven by owners who may not know the device is under the dashboard.

Aaron Schulman, the UCSD computer science professor who led the work, said the dealer-added system created a serious vulnerability in cars it was supposed to protect. The researchers are urging owners to check for the device and install the update manually.

How the bug works

The UCSD team found that KARR devices relied on a shared authentication key. Researchers said they located that key in the KARR smartphone app, reverse engineered the app’s command protocol, and built their own Android proof-of-concept app. With it, they could send Bluetooth commands that vulnerable KARR units accepted as legitimate.

The attack requires Bluetooth range, but the demonstrated effects are not subtle. In demos described by WIRED, the researchers used their app to unlock cars, disable ignition on parked vehicles, and set off horns and lights across multiple nearby cars. The flaw does not let an attacker start a vehicle, according to the researchers. They said, however, that a thief who can get inside quietly could use a commonly resold locksmith tool plugged into the dash to make a working key within minutes.

The device can also create a tracking problem. UCSD researcher Yibo Wei used WiGLE, an open radio-signal database, to help estimate deployment numbers from observed Bluetooth broadcasts and serial-number patterns. The researchers said those same broadcasts could let someone look up historical sightings of vulnerable vehicles and infer places where they are often parked.

In one UCSD scan near the university, the team said a regular Android phone detected 97 vehicles with KARR devices in 20 minutes. The researchers said the systems are common in Southern California but have been found across the United States and in other countries.

What owners should do

Acrisure Protection Group said in a statement to WIRED that the issue is complex and presents low real-world risk, but that it developed a firmware update to address it. The company said it will notify users through the KARR Security app, the KARR website, and dealer communications.

UCSD said owners who already use the KARR Security app should receive an update alert. Owners who do not have the app must install the KARR Security System app for Android or iOS, connect it to the vehicle’s KARR unit, then use the customer service and firmware update options.

Drivers can look for a KARR sticker on the driver-side window, an SWDS sticker for SouthWest Dealer Services, or a small blinking-light button under the dashboard, according to UCSD. The researchers said some inactive units still beacon and accept Bluetooth commands while the car is on and for up to 10 minutes after shutdown.

UCSD told Acrisure about the vulnerability in January of last year, WIRED reported. The fix arrived roughly 18 months later, shortly before the researchers’ planned presentations at Defcon and the Usenix security conference. Stefan Savage, a UCSD professor who was not part of this project but previously helped demonstrate car hacking against steering and brakes, told WIRED the problem is unusually hard to defend against because carmakers cannot patch it and many owners do not know the dealer-installed hardware exists.

This story draws on original reporting from WIRED.

More Internet/

view all ↗