A critical Bluetooth vulnerability in the dealer-installed KARR Security System exposes more than 2.2 million vehicles across the United States to remote unlocking, immobilization, and horn/light manipulation attacks by anyone within Bluetooth range.
San Diego disclosed the flaw after finding that the aftermarket alarm commonly installed by dealerships including Honda, Toyota, Mazda, Ford, and Jeep lots in Southern California from 2017 through 2026 relies on a shared authentication key hardcoded into the official KARR smartphone app.
The vulnerability stems from a universal Bluetooth authentication key that researchers extracted while reverse-engineering the KARR app’s communications protocol, resembling classic Bluetooth impersonation attacks against trusted peripherals.
KARR Car Alarm Flaw
Because the key is shared across all affected devices rather than unique per vehicle, the UCSD team built a proof-of-concept Android application that impersonated the legitimate KARR software and successfully sent unauthorized commands to nearby alarms.
Using this PoC, Andrew demonstrated they could unlock vehicles, disable alarms, sound horns, flash lights, and prevent parked vehicles from starting, though the flaw does not permit remote engine start or control of a moving vehicle.
Deactivated units remain dangerously exposed: even when a buyer declines the paid KARR service, the hardware stays wired in and continues broadcasting and accepting Bluetooth signals while the engine runs and for up to 10 minutes afterward.
UC San Diego used the crowdsourced wireless-signal database WiGLE to estimate deployment at over 2.2 million Bluetooth-enabled KARR units nationwide, and detected signals from 97 KARR-equipped vehicles during a single 20-minute drive near campus using a standard Android phone.
This same broadcast behavior creates a secondary privacy exposure, potentially allowing historical WiGLE records to reveal a targeted vehicle’s frequent locations.
Acrisure Protection Group, which markets KARR, released a firmware patch on July 20, 2026, roughly 18 months after initial disclosure.
A company spokesperson characterized the attack as “highly complex” with “low risk under real-world conditions,” while confirming remediation efforts through the KARR app, website, and dealer communications.
Neither UCSD nor Wired found evidence of in-the-wild exploitation, though the universal key significantly lowers the attack complexity since a single technique compromises all affected devices rather than requiring vehicle-specific exploits.
Andrew notes that installing the KARR Security app and applying the update remains the primary mitigation, though owners must first manually verify whether the hardware is present in their vehicle.
Detection and Mitigation
Owners should check for KARR or SWDS (SouthWest Dealer Services) window stickers, or a small blinking-light button beneath the dashboard, since roughly half of affected owners never requested or knowingly received the device.
Remediation requires downloading the KARR Security app for iOS or Android, connecting to the vehicle’s alarm unit, and navigating to customer service followed by a firmware update.
- Check driver-side window for KARR or SWDS branding
- Inspect underneath dashboard for blinking-light module
- Download KARR Security app (iOS/Android) if not already installed
- Connect app to vehicle and select customer service, then firmware update
- Contact selling dealership or KARR support if hardware can’t be identified
Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN.