California-bought cars can be hijacked via Bluetooth

sbulaev2 pts0 comments

Millions of California-bought cars can be hijacked via Bluetooth

Jump to main content

Search

REG AD

security

Millions of California-bought cars can be hijacked via Bluetooth

Aftermarket dealer-installed KARR/SWDS security systems all use the same secure key, say UCSD researchers

Brandon Vigliarolo

Brandon<br>Vigliarolo

GOVERNMENT AND IT NEWS REPORTER

Published<br>thu 23 Jul 2026 // 17:12 UTC

At least 2.2 million vehicles fitted with dealer-installed KARR and SWDS security systems are vulnerable to nearby Bluetooth attacks that can unlock doors or prevent a stopped vehicle from starting, according to researchers at the University of California San Diego.

A KARR security system sticker in a vehicle window<br>David Baillot/UC San Diego Jacobs School of Engineering

An advance look at the research published by UCSD this week (the full writeup won’t be available until August 12) reveals that KARR and SWDS security devices manufactured by Acrisure contain a serious flaw: They “all … rely on the same secure key,” the researchers found.<br>What that means, according to the researchers, is that anyone who knows the key, has a device with a Bluetooth connection, and can get within five yards of an affected vehicle can unlock it, make the horn honk, flash the headlights, or even prevent it from starting.

REG AD

“Instead of smashing a window to get access to a vehicle, thieves could simply connect remotely via Bluetooth to the device inside the vehicle, and make it unlock car doors,” Jerry Yu, coauthor on the research and UCSD compsci graduate, said in the release.

REG AD

KARR/SWDS devices are installed by dealerships. Along with providing key fob-like functions, they also serve as an antitheft device, allowing dealers and buyers to track cars with the devices installed in the case of theft.<br>According to UCSD, the devices are typically sold as a paid upgrade at dealerships around the US. KARR says its products are available through more than 3,000 dealerships nationwide. Per the researchers, however, those devices remain active even if a buyer declines the service, meaning those who don’t have an active KARR/SWDS contract are still at risk.<br>“Removing the devices is not trivial,” UCSD compsci PhD candidate and paper co-author Yibo Wei said in the university’s report on the research. “You have to open up the dashboard and cut and reconnect the wires that are deeply intertwined with the car’s computers and ignition system.”<br>In other words, there are likely a lot of cars on the road with one of these units installed, and for many owners, a KARR or SWDS window sticker may be the only obvious indication.<br>The researchers said that most vulnerable vehicles were purchased in Southern California in the past nine years from Honda, Toyota, Mazda, Ford, and Jeep dealerships. Secondary market resales, however, mean affected vehicles can be found throughout the US and even as far away as Japan, the team noted. They also discovered a public database that stores information about equipped vehicles, according to UCSD.<br>For those worried their vehicle may be vulnerable, no need to worry: KARR Security has already released a firmware update for affected devices that can be installed by both active customers and those with an inactive security system; steps are included on the company’s website. It’s not clear if KARR is notifying customers of the need to update their security system - we asked, but the company didn’t directly respond to that question.<br>What KARR did tell us was that, in contrast to the UCSD finding that “all KARR-SWDS devices rely on the same secure key,” it claims that only a small percentage of devices “with certain Bluetooth-related components” are actually affected.

MORE CONTEXT

Pwn2Own Automotive 2026 uncovers 76 zero-days, pays out more than $1M

CAN do attitude: How thieves steal cars using network bus

Porsche panic in Russia as pricey status symbols forget how to car

Your next car might need 300 GB of RAM, and so will autonomous robots

“The vulnerability described in the research is highly complex and presents a low risk to customers under real-world conditions,” a KARR spokesperson told us. “Nevertheless, we responded promptly and developed a firmware update to address the issue.”

REG AD

The vulnerability was discovered serendipitously by the UCSD researchers years ago when they were doing research on credit card skimmers and spotted Bluetooth fingerprints they couldn’t identify. After figuring out they had spotted car security systems, the team started digging into the devices, and here we are.<br>We contacted the team to get more detail on their findings, but didn’t hear back. They’ll be presenting their work at DEF CON on August 9, and the USENIX Security conference on August 12. ®

bluetooth<br>hacking<br>automotive<br>security<br>hardware

REG AD

Systems

AMD attacks the rack with Helios systems that rival Nvidia's

Spec for spec, the House of Zen's first rack-scale AI compute platform is bigger and faster than...

karr security devices bluetooth ucsd swds

Related Articles