VYPR
vulnerabilityPublished Jul 23, 2026· 1 source

Bluetooth Vulnerability in KARR Security System Exposes Millions of Vehicles to Remote Attacks

A widespread Bluetooth vulnerability in aftermarket KARR Security Systems allows attackers to remotely unlock doors, control alarms, and immobilize approximately 2.2 million vehicles.

A significant security flaw has been identified in the aftermarket KARR Security System, potentially exposing around 2.2 million vehicles to remote attacks. Researchers from the University of California, San Diego, discovered that the vulnerability allows unauthorized individuals within Bluetooth range to unlock vehicle doors, control alarm systems, and even immobilize the engine. This issue stems from a universal authentication key embedded within all KARR devices, which researchers were able to extract by reverse-engineering the official KARR mobile application. This extraction enabled them to create a proof-of-concept Android application capable of impersonating legitimate users and issuing commands to affected vehicles.

The implications of this vulnerability are far-reaching, particularly because the KARR system is commonly installed by dealerships on vehicles before sale, often remaining in place even if the owner does not activate or pay for the service. This practice has resulted in a large installed base of potentially vulnerable systems, many of which continue to emit Bluetooth signals. While the attack does not allow for remote driving or control of a moving vehicle, it significantly lowers the barrier for theft by providing easy, silent access to the vehicle's interior. The researchers demonstrated the exploit's scalability, noting that it becomes straightforward to execute once the universal key is known.

Mitigating this vulnerability presents a unique challenge as the KARR system is not integrated with the vehicle manufacturers' native systems. Consequently, traditional over-the-air updates or manufacturer-initiated recalls are not applicable. Acrisure Protection Group, the entity behind KARR, released a firmware patch on July 20, following responsible disclosure in January 2025. However, vehicle owners must proactively identify the KARR hardware and manually install the update through the KARR mobile app. This manual process places a significant burden on owners to be aware of and address the potential security risk.

Beyond the direct threat of exploitation, the vulnerability also raises privacy concerns. The KARR system continuously emits identifiable Bluetooth signals, even when the vehicle is parked or shortly after shutdown. Researchers utilized crowdsourced radio signal data, including information from the WiGLE wireless tracking database, to estimate the widespread deployment of these systems. They showed how historical signal data could potentially be used to map vehicle movement patterns or identify frequently visited locations, adding another layer of risk for unsuspecting owners.

To address the issue, vehicle owners are advised to check for KARR or SWDS branding, often found on the driver's side windows or beneath the dashboard. If the system is present, installing the KARR Security app and applying the latest firmware update is the primary recommended mitigation. For individuals who cannot confirm the presence of the system or are unable to complete the update, contacting their dealership or KARR support is the next best step. This incident underscores a broader challenge in automotive cybersecurity, where third-party hardware can introduce significant security gaps that bypass established manufacturer controls, leaving both consumers and manufacturers with limited visibility and delayed response capabilities.

The researchers' findings highlight the critical need for better oversight and security practices concerning dealer-installed aftermarket systems. As vehicles become more connected, the security of every component, including those added post-manufacturing, becomes paramount. The widespread nature of this vulnerability, affecting millions of vehicles, serves as a stark reminder of the potential attack surface created by such systems and the importance of proactive security measures for all vehicle hardware.

Synthesized by Vypr AI