2M Cars with KARR Anti-Theft Systems Are at Higher Risk of Theft

leecoursey1 pts0 comments

2 Million Cars with Anti-Theft Systems Installed by Dealers are at Higher Risk of Theft

story

-->

2 Million Cars with Anti-Theft Systems Installed by Dealers are at Higher Risk of Theft

A vulnerability in systems installed by dealers in Southern California since 2017 is getting fixed by the system manufacturer. But car owners need to be aware.

Watch this video with audio descriptions

Media contact:

Ioana Patringenaru

ipatrin@ucsd.edu

Published Date

July 21, 2026

Media contact:

Ioana Patringenaru

ipatrin@ucsd.edu

Share This:

Share this story on Linkedin

Share this story on Facebook

Share this story on Threads

Share this story on Twitter

Share this story via email

Article Content

Key Takeaways

At least 2.2 million cars on the road today are vulnerable to an attack that allows thieves to unlock doors via a Bluetooth connection<br>Most of the vulnerable vehicles were bought at Honda, Toyota, Mazda, Ford, and Jeep dealerships in Southern California from 2017 to today<br>Many vulnerable cars display a sticker with the word “KARR” or “SWDS” on the driver’s-side window<br>The company selling these devices, Acrisure, released a patch to fix the vulnerability on July 20, 2026

Photo gallery

At least 2.2 million cars on the road today are vulnerable to an attack that allows thieves to lock and unlock doors and immobilize vehicle engines remotely via a Bluetooth connection, computer scientists at the University of California San Diego have found.

Attackers can get access to cars from as far as five yards away. Most of the vulnerable vehicles were bought at Honda, Toyota, Mazda, Ford, and Jeep dealerships in Southern California from 2017 to today. But because these vehicles are resold on the second-hand market, several hundred thousand vulnerable vehicles can also be found throughout the United States, Canada and even as far as Japan. Many vulnerable cars display a sticker with the word &ldquo;KARR&rdquo; or &ldquo;SWDS&rdquo; on the driver&rsquo;s-side window.

The vulnerability is due to a device controlled via a smartphone app that is typically installed by dealerships to manage vehicle inventory and prevent theft. The device, installed underneath the bottom of the dashboard on the driver&rsquo;s side, connects vehicle and app via Bluetooth. The app makes the device perform functions similar to a key fob: lock and unlock doors as well as honk a horn and flash headlights as a warning. In addition, the device can prevent the car from starting as long as the car isn&rsquo;t already running.

All KARR-SWDS devices rely on the same secure key – meaning that once the researchers cracked that key, they had access to all the cars equipped with these devices. It&rsquo;s a bit like setting all passwords for a line of devices to 1234 and making it impossible to change the password.

When a dealership sells a vehicle, they market the device and app as a paid upgrade – an anti-theft tool as well as a tool to control the car via an app. Even if the buyer declines the upgrade, the device remains active, still leaving the vehicle vulnerable to an attacker in certain situations.

The company manufacturing these devices, Acrisure, released a patch to fix the vulnerability on July 20, 2026. The fix requires downloading an app. &ldquo;Many car owners don&rsquo;t even know that their vehicle is vulnerable. So we wanted to make sure they were aware by publishing this study,&rdquo; said Aaron Schulman, a professor in the UC San Diego Department of Computer Science and Engineering, and one of the study&rsquo;s senior authors.

The vulnerability could allow thieves to steal cars more easily. &ldquo;Instead of smashing a window to get access to a vehicle, thieves could simply connect remotely via Bluetooth to the device inside the vehicle, and make it unlock car doors,&rdquo; said Jerry Yu, who earned a master's in computer science at UC San Diego and the paper&rsquo;s co-first author. Once the car is unlocked, attackers can use a variety of tools available to locksmiths to then start the car and drive away.

The researchers, led by Schulman, will detail how they discovered the vulnerability and reverse-engineered it at the DEF CON conference Aug. 9 in Las Vegas and the USENIX Security conference Aug. 12 in Baltimore, Md.

In the study, researchers identified at least 1.4 million vulnerable vehicles, but further analysis by the UC San Diego researchers increased that number to an estimated 2.2 million – at least.

This sticker, found on cars sold after 2017 on the driver&rsquo;s side window, indicates that the vehicle likely has had a vulnerable system installed by a dealer.

Photos: David Baillot/University of California San Diego/Jacobs School of Engineering

Different levels of vulnerability

In addition to Acrisure, Rockledge, a car security and insurance company, makes similar devices. The researchers found these devices may also be vulnerable, but are more difficult to attack. An attacker would need to be there when a...

vulnerable cars vehicle theft rsquo vulnerability

Related Articles